---
id: CVE-2025-54471
title: |-
  NeuVector used a hard-coded cryptographic key embedded in the source 
  code
summary: |-
  NeuVector used a hard-coded cryptographic key embedded in the source 
  code. At compilation time, the key value was replaced with the secret 
  key value and used to encrypt sensitive configurations  when NeuVector 
  stores the data.
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-321
published: '2025-10-30'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T10:10:00.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-54471'
references:
  - url: 'https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-54471'
    label: meissner@suse.de
  - url: >-
      https://github.com/neuvector/neuvector/security/advisories/GHSA-h773-7gf7-9m2x
    label: meissner@suse.de
tags:
  - nvd
epss: 0.00268
epssPercentile: 0.1734
ingestedAt: '2026-10-08T10:28:19.032Z'
---

## Overview

NeuVector used a hard-coded cryptographic key embedded in the source 
code. At compilation time, the key value was replaced with the secret 
key value and used to encrypt sensitive configurations  when NeuVector 
stores the data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
