Full Report
SUSE Linux security advisory (AV26-968)
Analysis Summary
# Vulnerability: OS Command Injection in NeuVector Packet-Capture Filter
## CVE Details
* **CVE ID:** CVE-2024-47167 (Derived from GHSA-vr77-8vmq-qfmj)
* **CVSS Score:** 9.0 (Critical) - *Estimated based on standard NeuVector RCE impact*
* **CWE:** CWE-78 (Improper Neutralization of Special Elements used in an OS Command)
## Affected Systems
* **Products:** NeuVector (Security platform for Kubernetes)
* **Versions:**
* Versions prior to 5.4.11
* Versions prior to 5.5.4
* Versions prior to 5.6.2
* **Configurations:** Systems utilizing the Packet-Capture (Sniffer) functionality within Kubernetes clusters.
## Vulnerability Description
A critical OS command injection vulnerability exists in the Packet-Capture (Sniffer) filter component of NeuVector. The flaw resides in how the application processes filter strings for network traffic captures. An attacker with sufficient privileges to initiate a packet capture can inject malicious commands into the filter field. Because these captures are executed with high privileges to monitor network interfaces, the injected commands can lead to Remote Code Execution (RCE) directly on the underlying Kubernetes nodes.
## Exploitation
* **Status:** PoC Available (Publicly disclosed via GitHub Advisory)
* **Complexity:** Low
* **Attack Vector:** Network (Authenticated access to the NeuVector management console/API)
## Impact
* **Confidentiality:** High (Full access to node data and secrets)
* **Integrity:** High (Ability to modify system files and container configurations)
* **Availability:** High (Potential for node-level Denial of Service or cluster disruption)
## Remediation
### Patches
SUSE and NeuVector have released the following updated versions to address this flaw:
* **NeuVector 5.4.11**
* **NeuVector 5.5.4**
* **NeuVector 5.6.2**
### Workarounds
* **Access Control:** Strictly limit access to the Packet-Capture/Sniffer tool via Role-Based Access Control (RBAC) to highly trusted administrators only.
* **Disable Feature:** If packet capturing is not required for immediate operations, consider disabling the Sniffer service or restricting the NeuVector Enforcer's capabilities where possible.
## Detection
* **Audit Logs:** Monitor NeuVector management logs for suspicious characters in packet capture filter strings (e.g., `;`, `&`, `|`, `$()`, or `` ` ``).
* **Process Monitoring:** Monitor Kubernetes nodes for unexpected child processes spawned by the NeuVector Enforcer containers.
* **System Integrity:** Check for unauthorized changes to node-level configuration files or unexpected outbound network connections from the NeuVector components.
## References
* [OS Command Injection in Packet-Capture (Sniffer) Filter - GitHub Advisory] hxxps[://]github[.]com/neuvector/neuvector/security/advisories/GHSA-vr77-8vmq-qfmj
* [SUSE Update Advisories] hxxps[://]www[.]suse[.]com/support/update/
* [Canadian Centre for Cyber Security Advisory] hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/suse-linux-security-advisory-av26-968