CVE-2019-18905 Details
Description
A Insufficient Verification of Data Authenticity vulnerability in autoyast2 of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allows remote attackers to MITM connections when deprecated and unused functionality of autoyast is used to create images. This issue affects: SUSE Linux Enterprise Server 12 autoyast2 version 4.1.9-3.9.1 and prior versions. SUSE Linux Enterprise Server 15 autoyast2 version 4.0.70-3.20.1 and prior versions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00050.html | CVE | |
| https://bugzilla.suse.com/show_bug.cgi?id=1140711 | CVE | Issue TrackingVendor Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00050.html | [email protected] | |
| https://bugzilla.suse.com/show_bug.cgi?id=1140711 | [email protected] | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | [email protected] |
| CWE-345 | Insufficient Verification of Data Authenticity | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| opensuse autoyast2 | <= 4.1.9-3.9.1 <= 4.0.70-3.20.1 |
CPE
Remediation
| |
| suse linux enterprise server | 12 - 15 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| May 23, 2020 | CVE Modified | [email protected] |
| Apr 6, 2020 | Initial Analysis | [email protected] |
| Apr 3, 2020 | CVE Modified | [email protected] |