CVE-2019-18905
Deprecated functionality in autoyast2 automatically imports gpg keys without checking them
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A Insufficient Verification of Data Authenticity vulnerability in autoyast2 of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allows remote attackers to MITM connections when deprecated and unused functionality of autoyast is used to create images. This issue affects: SUSE Linux Enterprise Server 12 autoyast2 version 4.1.9-3.9.1 and prior versions. SUSE Linux Enterprise Server 15 autoyast2 version 4.0.70-3.20.1 and prior versions.
Una vulnerabilidad de Verificación Insuficiente de la Autenticidad de Datos en autoyast2 de SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, permite a atacantes remotos conexiones de tipo MITM cuando es usada la funcionalidad obsoleta y no utilizada autoyast para crear imágenes. Este problema afecta a: autoyast2 de SUSE Linux Enterprise Server 12 versión 4.1.9-3.9.1 y versiones anteriores. autoyast2 de SUSE Linux Enterprise Server 15 versión 4.0.70-3.20.1 y versiones anteriores.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-11-12 CVE Reserved
- 2020-04-03 CVE Published
- 2023-04-07 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-345: Insufficient Verification of Data Authenticity
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00050.html | 2020-05-23 | |
https://bugzilla.suse.com/show_bug.cgi?id=1140711 | 2020-05-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Opensuse Search vendor "Opensuse" | Autoyast2 Search vendor "Opensuse" for product "Autoyast2" | <= 4.1.9-3.9.1 Search vendor "Opensuse" for product "Autoyast2" and version " <= 4.1.9-3.9.1" | - |
Affected
| in | Suse Search vendor "Suse" | Linux Enterprise Server Search vendor "Suse" for product "Linux Enterprise Server" | 12 Search vendor "Suse" for product "Linux Enterprise Server" and version "12" | - |
Safe
|
Opensuse Search vendor "Opensuse" | Autoyast2 Search vendor "Opensuse" for product "Autoyast2" | <= 4.0.70-3.20.1 Search vendor "Opensuse" for product "Autoyast2" and version " <= 4.0.70-3.20.1" | - |
Affected
| in | Suse Search vendor "Suse" | Linux Enterprise Server Search vendor "Suse" for product "Linux Enterprise Server" | 15 Search vendor "Suse" for product "Linux Enterprise Server" and version "15" | - |
Safe
|