PT-2024-12298 · Suse · Suse Manager Server Module+1
Frantisek Kobzik
·
Published
2024-02-15
·
Updated
2024-10-29
·
CVE-2023-32189
CVSS v3.1
5.9
Medium
| Vector | AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SUSE Manager Server Module version 4.3
Description
The issue is related to insecure handling of ssh keys used to bootstrap clients, allowing local attackers to potentially gain access to the keys. This could lead to unauthorized access.
Recommendations
For SUSE Manager Server Module version 4.3, upgrade the affected component immediately to protect SSH keys and secure access.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse Manager Server Module
Suse