CVE-2025-54470 - CVE House
Back to Database
Status published High CVE-2025-54470

NeuVector telemetry sender is vulnerable to MITM and DoS

Vulnerability Description

This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When this option is enabled, NeuVector sends anonymous telemetry data to the telemetry server. In affected versions, NeuVector does not enforce TLS certificate verification when transmitting anonymous cluster data to the telemetry server. As a result, the communication channel is susceptible to man-in-the-middle (MITM) attacks, where an attacker could intercept or modify the transmitted data. Additionally, NeuVector loads the response of the telemetry server is loaded into memory without size limitation, which makes it vulnerable to a Denial of Service(DoS) attack

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-54470

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

neuvector
Vulnerable Versions:
5.3.0, 5.4.0, 0.0.0-20230727023453-1c4957d53911

Timeline

Official Publish: October 30th, 2025
Last Modified: October 30th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Weaknesses (CWE)