A Insufficient Verification of Data Authenticity vulnerability in autoyast2 of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allows remote attackers to MITM connections when deprecated and unused functionality of autoyast is used to create images. This issue affects: SUSE Linux Enterprise Server 12 autoyast2 version 4.1.9-3.9.1 and prior versions. SUSE Linux Enterprise Server 15 autoyast2 version 4.0.70-3.20.1 and prior versions.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: suse
Published: 2020-04-03T11:00:16.880502Z
Updated: 2024-09-17T02:52:07.503Z
Reserved: 2019-11-12T00:00:00
Link: CVE-2019-18905
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-04-03T11:15:12.743
Modified: 2024-11-21T04:33:49.097
Link: CVE-2019-18905
Redhat
No data.