Opensuse Cryptctl vulnerabilities
2 known vulnerabilities affecting opensuse/cryptctl.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2
Vulnerabilities
Page 1 of 1
CVE-2019-18906CRITICALCVSS 9.8fixed in 2.42021-06-30
CVE-2019-18906 [CRITICAL] CWE-287 CVE-2019-18906: A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5,
A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server 4.0 allows attackers with access to the hashed password to use it without having to crack it. This issue affects: SUSE Linux Enterprise Server for SAP 12-SP5 cryptctl versions prior to 2.4. SUSE Manager Server 4.0 cryptctl version
nvd
CVE-2017-9270CRITICALCVSS 9.1v2.02018-03-01
CVE-2017-9270 [CRITICAL] CWE-22 CVE-2017-9270: In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files
In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files outside of the cryptctl key database.
nvd