Security Advisory
CVE-2025-66001
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote servers authenticity and integrity) for OpenID Connect is not enforced by default. As a result this may expose the system to man-in-the-middle (MITM) attacks.