CVE-2025-8077

Source
https://cve.org/CVERecord?id=CVE-2025-8077
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-8077.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-8077
Aliases
Downstream
Related
Published
2025-09-17T13:15:34.460Z
Modified
2026-04-10T05:36:08.781580Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability exists in NeuVector versions up to and including 5.4.5, where a fixed string is used as the default password for the built-in admin account. If this password is not changed immediately after deployment, any workload with network access within the cluster could use the default credentials to obtain an authentication token. This token can then be used to perform any operation via NeuVector APIs.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-8077.json"