NeuVector used a hard-coded cryptographic key embedded in the source
code. At compilation time, the key value was replaced with the secret
key value and used to encrypt sensitive configurations when NeuVector
stores the data.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-h773-7gf7-9m2x NeuVector is shipping cryptographic material into its binary
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 30 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Suse
Suse neuvector
Vendors & Products Suse
Suse neuvector

Thu, 30 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Oct 2025 10:00:00 +0000

Type Values Removed Values Added
Description NeuVector used a hard-coded cryptographic key embedded in the source code. At compilation time, the key value was replaced with the secret key value and used to encrypt sensitive configurations when NeuVector stores the data.
Title NeuVector is shipping cryptographic material into its binary
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2025-10-30T13:59:54.426Z

Reserved: 2025-07-23T08:11:16.426Z

Link: CVE-2025-54471

cve-icon Vulnrichment

Updated: 2025-10-30T13:59:51.238Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-30T10:15:35.400

Modified: 2025-10-30T15:03:13.440

Link: CVE-2025-54471

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-30T14:37:25Z