CVE Vulnerabilities

CVE-2025-54471

Use of Hard-coded Cryptographic Key

Published: Oct 30, 2025 | Modified: Oct 30, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

NeuVector used a hard-coded cryptographic key embedded in the source code. At compilation time, the key value was replaced with the secret key value and used to encrypt sensitive configurations when NeuVector stores the data.

Weakness

The product uses a hard-coded, unchangeable cryptographic key.

Potential Mitigations

References