CyberRota Analysis
AI-GeneratedNeuVector is vulnerable due to improper parameter handling, allowing authenticated users with specific permissions or access to internal gRPC certificate keys to inject OS commands into the privileged enforcer container. This vulnerability can lead to a complete compromise of the worker node, posing a significant risk to system integrity. Organizations using affected versions of NeuVector should prioritize remediation to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector’s internal gRPC certificate key pair the ability to inject OS commands in the privileged enforcer container, which can lead to the complete compromise of the worker node. This affects NeuVector 5.4 before 5.4.11, NeuVector 5.5 before 5.5.4, NeuVector 5.6 before 5.6.2 and potentially older versions.