CVE-2025-66001

🟡 Monitoruj

Brak wymuszenia weryfikacji TLS w NeuVector naraża system na ataki typu man-in-the-middle.

CVSS
8.8
EPSS
0.4%
Exploit
none
Vendor
Opis źródłowy (NVD)

NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and integrity) for OpenID Connect is not enforced by default. As a result this may expose the system to man-in-the-middle (MITM) attacks.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2026-01-08 11:15:43 UTC
Ostatnia modyfikacja (NVD)2026-10-07 09:10:00 UTC
Referencje