Vulnerabilities > Neuvector

DATE CVE VULNERABILITY TITLE RISK
2019-12-20 CVE-2019-19747 Weak Password Requirements vulnerability in Neuvector 3.1
NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by providing a valid username and an empty password (provided that the active directory server has not been configured to reject empty passwords).
network
low complexity
neuvector CWE-521
critical
9.8