Impact
NeuVector Manager exposes its /network/graph API without requiring authentication, allowing users to retrieve cached graph data that may contain sensitive network topology and other confidential information. The vulnerability stems from missing authorization checks and the retention of cached data, enabling unauthorized parties to read data they should not access. This leads to a confidentiality compromise as an attacker could reconstruct internal network structures and potentially identify assets or services requiring further exploitation.
Affected Systems
SUSE NeuVector Manager versions 5.4.9 and earlier are affected. The issue is present in the manager component responsible for handling network graph requests.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity of information disclosure. Although no EPSS score is available, the lack of authentication means that any network user who can reach the manager can exploit the flaw without additional prerequisites. The vulnerability is not listed in the CISA KEV catalog, but it remains a significant risk for organizations that expose the NeuVector API to external or untrusted networks. Attackers can obtain endpoints, services, and relationships within the internal network, facilitating subsequent lateral movement or targeted attacks.
OpenCVE Enrichment