PT-2026-94159 · Neuvector · Neuvector
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NeuVector versions prior to 5.4.11
NeuVector versions prior to 5.5.4
NeuVector versions prior to 5.6.2
Description
Improper parameter handling in the packet capture mechanism allows an authenticated user with namespaced Runtime Policies (write) permissions, or anyone with access to the internal gRPC certificate key pair, to perform OS command injection. By using a specially crafted filter, an attacker can execute commands within the privileged enforcer container, potentially leading to the complete compromise of the Kubernetes worker node.
Recommendations
Update to version 5.4.11 or later.
Update to version 5.5.4 or later.
Update to version 5.6.2 or later.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Neuvector