CVE-2025-66001
🟡 Monitoruj
Brak wymuszenia weryfikacji TLS w NeuVector naraża system na ataki typu man-in-the-middle.
CVSS
8.8
EPSS
0.4%
Exploit
none
Vendor
Opis źródłowy (NVD)
NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and integrity) for OpenID Connect is not enforced by default. As a result this may expose the system to man-in-the-middle (MITM) attacks.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2026-01-08 11:15:43 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 09:10:00 UTC |