PT-2024-12298 · Suse · Suse Manager Server Module+1

Frantisek Kobzik

·

Published

2024-02-15

·

Updated

2024-10-29

·

CVE-2023-32189

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SUSE Manager Server Module version 4.3
Description The issue is related to insecure handling of ssh keys used to bootstrap clients, allowing local attackers to potentially gain access to the keys. This could lead to unauthorized access.
Recommendations For SUSE Manager Server Module version 4.3, upgrade the affected component immediately to protect SSH keys and secure access.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2023-32189
OPENSUSE-SU-2024_0513-1
SUSE-SU-2024:0485-1
SUSE-SU-2024:0513-1

Affected Products

Suse Manager Server Module
Suse