CVE-2025-54467

Aliases:GHSA-w54x-xfxg-4gxqGO-2025-3919CGA-437g-5pwq-v3g3CGA-6rg9-7g9m-g8wrCGA-mv8h-7hpw-c2r2CGA-46mm-3mxp-8rrcCGA-6jjq-j8gr-grrqCGA-ph2h-vw8q-qv65CGA-xg9r-wgjx-gjqgCGA-xm82-rpf9-c27h
Advisory lineage Upstream: 0 Downstream: 3
Deferred
Published: 17 Sept 2025, 12:29
Last modified:17 Sept 2025, 13:19

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5.3 MEDIUM
v3.1 (cve.org)
EPSS Score
0.25% LOW
0% probability +0.21%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Sept 2025, 12:29
Published
Vulnerability first disclosed
17 Sept 2025, 13:19
Last Modified
Vulnerability information updated

Description

When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the password will appear in the NeuVector security event log.

CVSS Metrics

  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS Trends

Current EPSS score: 0.25% Percentile: 16%

Techniques & Countermeasures

  • CWE-522Insufficiently Protected Credentials

    The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Systems

  • chainguardneuvector-scanner

    < 0

  • chainguardneuvector-scanner-fips

    < 0

  • chainguardneuvector-scanner-task

    < 0

  • chainguardneuvector-scanner-task-fips

    < 0

  • wolfineuvector-scanner

    < 0

  • wolfineuvector-scanner-task

    < 0

  • github.com/neuvectorneuvector

    ≥ 5.0.0, < 5.4.6 | < 0.0.0-20250825231653-65d7e746ce84 | all | < 0.0.0-20250902144615-f9ddbdf42031

  • suseneuvector

    ≥ 5.0.0, < 5.4.6

References (6)