CVE-2025-53884

MEDIUM

NeuVector 5.0.0-5.4.5 - Use of a One-Way Hash without a Salt

Title source: llm
STIX 2.1

Description

NeuVector stores user passwords and API keys using a simple, unsalted hash. This method is vulnerable to rainbow table attack (offline attack where hashes of known passwords are precomputed).

Scores

CVSS v3 5.3
EPSS 0.0002
EPSS Percentile 7.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-759
Status published
Products (3)
neuvector/neuvector 0 - 0.0.0-20250825191744-da1a462074c3Go
neuvector/neuvector 5.0.0 - 5.4.6Go
SUSE/neuvector 5.0.0 - 5.4.6
Published Sep 17, 2025
Tracked Since Feb 18, 2026