VYPR
Critical severity9.8NVD Advisory· Published Dec 20, 2019· Updated Jun 17, 2026

CVE-2019-19747

CVE-2019-19747

Description

NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by providing a valid username and an empty password (provided that the active directory server has not been configured to reject empty passwords).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:neuvector:neuvector:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:neuvector:neuvector:*:*:*:*:*:*:*:*range: <=3.1
    • (no CPE)range: <3.1
  • NeuVector/NeuVectordescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.