PT-2026-7954 · Neuvector · Neuvector
Published
2026-02-12
·
Updated
2026-03-03
·
CVE-2025-67860
CVSS v3.1
3.8
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NeuVector versions prior to 4.072
Description
The NeuVector scanner insecurely handles passwords as command arguments. The scanner process accepts registry and controller credentials as command-line arguments, potentially exposing sensitive credentials to local users. This could allow unauthorized access to registries or the NeuVector controller, potentially enabling image manipulation, information disclosure, or further lateral movement within the environment. The impact severity for confidentiality, integrity and availability is dependent on the permissions the leaked credentials have on their services.
Recommendations
Upgrade to NeuVector scanner version 4.072 or later.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Neuvector