CVE-2019-18905

MEDIUM

SUSE Linux Enterprise Server <12,15 - Info Disclosure

Title source: llm
STIX 2.1

Description

A Insufficient Verification of Data Authenticity vulnerability in autoyast2 of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allows remote attackers to MITM connections when deprecated and unused functionality of autoyast is used to create images. This issue affects: SUSE Linux Enterprise Server 12 autoyast2 version 4.1.9-3.9.1 and prior versions. SUSE Linux Enterprise Server 15 autoyast2 version 4.0.70-3.20.1 and prior versions.

References (2)

Core 2
Core References
Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.suse.com/show_bug.cgi?id=1140711

Scores

CVSS v3 4.8
EPSS 0.0011
EPSS Percentile 28.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L

Details

CWE
CWE-345
Status published
Products (1)
opensuse/autoyast2 < 4.1.9-3.9.1
Published Apr 03, 2020
Tracked Since Feb 18, 2026