Impact
The vulnerability arises from incomplete validation of pod identifier uniqueness in the aws-network-policy-agent. Prior to version 1.4.0, the agent allows pod names and namespaces that produce identical identifiers. An attacker who can create pods with engineered names can cause identifier collisions that allow traffic to bypass NetworkPolicy rules on other namespaces. This effectively nullifies network segmentation and permits unauthorized communication to resources that should be isolated.
Affected Systems
The flaw affects Amazon EKS clusters that use Amazon VPC CNI and the network policy agent. AWS:amazon-vpc-cni-k8s and AWS:aws-network-policy-agent versions lower than 1.22.4 and 1.4.0, respectively, are vulnerable. Any authenticated user capable of creating or updating pods can exploit the bug, as the unique identifier check is missing from those releases.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, but the EPSS score of <1% indicates a low probability of exploitation in the current environment. The vulnerability is not listed in CISA KEV, suggesting no widespread exploitation has been observed. Exploitation requires authenticated access to the Kubernetes API and the ability to create pods; once a collision is achieved, the attacker can inject traffic that bypasses NetworkPolicy scopes, potentially enabling lateral movement or data exfiltration across namespaces.
OpenCVE Enrichment