CVE-2013-3710

SUSE Lifecycle Management Server < 1.3.7 - Cryptographic Protection Bypass via Static Secret Key

Title source: llm
STIX 2.1

Description

SUSE Lifecycle Management Server (SLMS) before 1.3.7 does not generate a new secret key when the service starts, which allows remote attackers to defeat intended cryptographic protection mechanisms by leveraging knowledge of this key from a product installation elsewhere.

References (3)

Core 3
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.novell.com/show_bug.cgi?id=852101
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/100653

Scores

EPSS 0.0141
EPSS Percentile 80.8%

Details

CWE
CWE-310
Status published
Products (4)
novell/suse_lifecycle_management_server 1.0
novell/suse_lifecycle_management_server 1.1
novell/suse_lifecycle_management_server 1.2
novell/suse_lifecycle_management_server < 1.3
Published Dec 10, 2013
Tracked Since Feb 18, 2026