← back
CVE-2025-66001

NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM)

CVSS 8.8 HIGHEPSS 0.3%CWE-295
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
08 Jan 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and integrity) for OpenID Connect is not enforced by default. As a result this may expose the system to man-in-the-middle (MITM) attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
SUSE · neuvector

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →