{"id":"CVE-2025-54471","title":"NeuVector used a hard-coded cryptographic key embedded in the source \ncode","summary":"NeuVector used a hard-coded cryptographic key embedded in the source \ncode. At compilation time, the key value was replaced with the secret \nkey value and used to encrypt sensitive configurations  when NeuVector \nstores the data.","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-321"],"published":"2025-10-30","updated":"2026-10-08","sourceUpdated":"2026-10-08T10:10:00.227","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-54471","references":[{"url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-54471","label":"meissner@suse.de"},{"url":"https://github.com/neuvector/neuvector/security/advisories/GHSA-h773-7gf7-9m2x","label":"meissner@suse.de"}],"tags":["nvd"],"epss":0.00268,"epssPercentile":0.1734,"ingestedAt":"2026-10-08T10:28:19.032Z","slug":"CVE-2025-54471","body":"## Overview\n\nNeuVector used a hard-coded cryptographic key embedded in the source \ncode. At compilation time, the key value was replaced with the secret \nkey value and used to encrypt sensitive configurations  when NeuVector \nstores the data.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}