PT-2013-4577 · Suse · Suse Lifecycle Management Server

Published

2013-12-10

·

Updated

2013-12-12

·

CVE-2013-3710

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions SUSE Lifecycle Management Server (SLMS) versions prior to 1.3.7
Description The issue allows remote attackers to defeat intended cryptographic protection mechanisms by leveraging knowledge of a secret key from a product installation elsewhere, due to the service not generating a new secret key when it starts.
Recommendations For versions prior to 1.3.7, update to version 1.3.7 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3710

Affected Products

Suse Lifecycle Management Server