CVE Explorer
CVE-2025-8077
A vulnerability exists in NeuVector versions up to and including 5.4.5, where a fixed string is used as the default password for the built-in `admin` account. If this password is not changed immediately after deployment, any workload with network access within the cluster could use the default credentials to obtain an authentication token. This token can then be used to perform any operation via NeuVector APIs.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","packageName":"github.com/neuvector/neuvector","product":"neuvector","vendor":"SUSE","versions":[{"lessThan":"5.4.6","status":"affected","version":"5.0.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6ed324307a83f898cd503a0ba08196fd20a64743fe59c3c58f028bee48189655 · sha256:7d26d4da7fd0b167… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6ed324307a83f898cd503a0ba08196fd20a64743fe59c3c58f028bee48189655 · sha256:7d26d4da7fd0b167… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-1393","description":"CWE-1393: Use of Default Password","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6ed324307a83f898cd503a0ba08196fd20a64743fe59c3c58f028bee48189655 · sha256:7d26d4da7fd0b167… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-8077"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6ed324307a83f898cd503a0ba08196fd20a64743fe59c3c58f028bee48189655 · sha256:7d26d4da7fd0b167… · /containers/cna/references/0
{"url":"https://github.com/neuvector/neuvector/security/advisories/GHSA-8pxw-9c75-6w56"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6ed324307a83f898cd503a0ba08196fd20a64743fe59c3c58f028bee48189655 · sha256:7d26d4da7fd0b167… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.