CVE-2013-3710: Medium severity suse lifecycle management server vulnerability
SUSE Lifecycle Management Server (SLMS) before 1.3.7 does not generate a new secret key when the service starts, which allows remote attackers to defeat intended cryptographic protection mechanisms by leveraging knowledge of this key from a product installation elsewhere.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3710?
CVE-2013-3710 has a medium severity rating due to the potential for remote attackers to exploit the lack of a newly generated secret key.
How do I fix CVE-2013-3710?
To fix CVE-2013-3710, upgrade to SUSE Lifecycle Management Server version 1.3.7 or later.
What versions of SUSE Lifecycle Management Server are affected by CVE-2013-3710?
CVE-2013-3710 affects versions 1.0, 1.1, 1.2, and all versions before 1.3.7 of SUSE Lifecycle Management Server.
What vulnerability does CVE-2013-3710 expose in SUSE Lifecycle Management Server?
CVE-2013-3710 exposes the service to potential cryptographic protection failures due to not generating a new secret key at startup.
Who is affected by CVE-2013-3710?
Organizations using vulnerable versions of SUSE Lifecycle Management Server are at risk of having their cryptographic protections compromised.