Junglewise Threat Intelligence

CVE-2025-53884: SUSE NeuVector insecure password storage via unsalted hashes

CVE-2025-53884 · Severity: medium · CVSS 5.3 · Published 2025-08-28

Technologies: Suse NeuVector, github.com/neuvector/neuvector (Go). Vendors: Suse, Go.

Executive brief

NeuVector, a container security platform, was found to store user passwords and API keys using insecure, unsalted hashes. If an attacker gains access to the underlying database, they could use precomputed tables to quickly crack these passwords and keys. This could lead to unauthorized access to the security management console and sensitive cloud infrastructure.

Technical details

NeuVector was identified as using insecure password storage (CWE-759, CWE-916) by utilizing unsalted hashes for user credentials and API keys. This lack of salting allows for efficient offline cracking using rainbow tables if the hash data is exfiltrated. The vulnerability is addressed in version 5.4.6 by implementing PBKDF2 with a cryptographically secure 16-character salt. Post-patch, users must re-authenticate and API keys must be used at least once to trigger the regeneration of hashes using the new secure method.

Affected products

  • SUSE NeuVector < 5.4.6

Timeline

  • 2025-08-26: disclosed
  • 2025-08-28: advisory

References

Related threats