Vulnerabilidad · Publicado 28/09/2026
NeuVector versiones 5.4 (anteriores a 5.4.11) y 5.5 presenta manejo inadecuado de parámetros que permite a usuarios autenticados con permisos de escritura en Políticas Runtime o acceso a claves gRPC internas inyectar comandos del sistema operativo en contenedores enforcer privilegiados. Esto resulta en compromiso total del nodo worker. Afecta principalmente a infraestructuras containerizadas en Azure, AWS y datacenters locales de la región.
Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector’s internal gRPC certificate key pair the ability to inject OS commands in the privileged enforcer container, which can lead to the complete compromise of the worker node. This affects NeuVector 5.4 before 5.4.11, NeuVector 5.5 before 5.5.4, NeuVector 5.6 before 5.6.2 and potentially older versions.
Score: 8.8/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-78
Publicado en NIST NVD.