Impact
A vulnerability in Neuvector allows one user to acquire another user's authenticated session when multiple SAML or OpenID Connect login attempts happen concurrently. The flaw results in an unauthorized session takeover, giving the attacker full access to the victim’s account. This issue is a classic case of session fixation (CWE-384) and directly compromises confidentiality and integrity of user data.
Affected Systems
The affected product is Neuvector from SUSE, version 5.6.1. Any installation that relies on SAML or OIDC authentication may be impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability, but the EPSS score of less than 1% shows a very low probability of exploitation at this time. The vulnerability is not currently listed in CISA’s KEV table. Although no specific exploitation environment is detailed, the likely vector involves feeding concurrent login requests to the SSO endpoint, enabling session collision. The impact is limited to individual accounts and not to system-wide compromise unless orchestration or privileged user accounts are involved.
OpenCVE Enrichment