CVE Explorer
CVE-2025-64513
Milvus is an open-source vector database built for generative AI applications. An unauthenticated attacker can exploit a vulnerability in versions prior to 2.4.24, 2.5.21, and 2.6.5 to bypass all authentication mechanisms in the Milvus Proxy component, gaining full administrative access to the Milvus cluster. This grants the attacker the ability to read, modify, or delete data, and to perform privileged administrative operations such as database or collection management. This issue has been fixe
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"milvus","vendor":"milvus-io","versions":[{"status":"affected","version":"< 2.4.24"},{"status":"affected","version":">= 2.5.0, < 2.5.21"},{"status":"affected","version":">= 2.6.0, < 2.6.5"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:5714941eca781bfc8c8345640ae605e9d7b6a0197c360b242b0929f2baa155db · sha256:bec7bc441afcdb54… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.3,"baseSeverity":"CRITICAL","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:5714941eca781bfc8c8345640ae605e9d7b6a0197c360b242b0929f2baa155db · sha256:bec7bc441afcdb54… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-287","description":"CWE-287: Improper Authentication","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:5714941eca781bfc8c8345640ae605e9d7b6a0197c360b242b0929f2baa155db · sha256:bec7bc441afcdb54… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/milvus-io/milvus/pull/45379","tags":["x_refsource_MISC"],"url":"https://github.com/milvus-io/milvus/pull/45379"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5714941eca781bfc8c8345640ae605e9d7b6a0197c360b242b0929f2baa155db · sha256:bec7bc441afcdb54… · /containers/cna/references/1
{"name":"https://github.com/milvus-io/milvus/pull/45383","tags":["x_refsource_MISC"],"url":"https://github.com/milvus-io/milvus/pull/45383"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5714941eca781bfc8c8345640ae605e9d7b6a0197c360b242b0929f2baa155db · sha256:bec7bc441afcdb54… · /containers/cna/references/2
{"name":"https://github.com/milvus-io/milvus/pull/45391","tags":["x_refsource_MISC"],"url":"https://github.com/milvus-io/milvus/pull/45391"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5714941eca781bfc8c8345640ae605e9d7b6a0197c360b242b0929f2baa155db · sha256:bec7bc441afcdb54… · /containers/cna/references/3
{"name":"https://github.com/milvus-io/milvus/security/advisories/GHSA-mhjq-8c7m-3f7p","tags":["x_refsource_CONFIRM"],"url":"https://github.com/milvus-io/milvus/security/advisories/GHSA-mhjq-8c7m-3f7p"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5714941eca781bfc8c8345640ae605e9d7b6a0197c360b242b0929f2baa155db · sha256:bec7bc441afcdb54… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.