PT-2024-12298 · Suse · Suse Manager Server Module+1

·

CVE-2023-32189

·

Published

2024-02-15

·

Updated

2024-10-29

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SUSE Manager Server Module version 4.3
Description The issue is related to insecure handling of ssh keys used to bootstrap clients, allowing local attackers to potentially gain access to the keys. This could lead to unauthorized access.
Recommendations For SUSE Manager Server Module version 4.3, upgrade the affected component immediately to protect SSH keys and secure access.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-32189
OPENSUSE-SU-2024_0513-1
SUSE-SU-2024:0485-1
SUSE-SU-2024:0513-1

Affected Products

Suse Manager Server Module
Suse