CVE-2023-32188: Neuvector

Critical severity, CVSS 9.4. EPSS: 0.6% chance of exploitation in the next 30 days.

A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.

Affected products

  • Neuvector Neuvector: before 0.0.0-20231003121714-be746957ee7c (fixed in 0.0.0-20231003121714-be746957ee7c)
  • Suse Neuvector: before 0.0.0-20231003121714-be746957ee7c (fixed in 0.0.0-20231003121714-be746957ee7c)

Published 2024-10-16. Last modified 2026-06-17.