PT-2023-23657 · Neuvector · Neuvector

Dejan Zelic

·

Published

2023-10-06

·

Updated

2024-10-16

·

CVE-2023-32188

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions NeuVector versions prior to 5.2.2
Description A user can reverse engineer the JSON Web Token (JWT) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector, potentially leading to Remote Code Execution (RCE).
Recommendations For versions prior to 5.2.2, upgrade to NeuVector version 5.2.2 or later and use the latest Helm chart (2.6.3+). As a temporary workaround, users can replace the Manager & Controller certificate manually by following the instructions provided in the documentation. However, upgrading to 5.2.2 and replacing the Manager/REST API certificate is recommended to provide additional security enhancements to prevent possible attempted exploit and resulting RCE.

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-32188
GHSA-622H-H2P8-743X
GO-2024-3201

Affected Products

Neuvector