CVE-2013-3710

SUSE Lifecycle Management Server (SLMS) before 1.3.7 does not generate a new secret key when the service starts, which allows remote attackers to defeat intended cryptographic protection mechanisms by leveraging knowledge of this key from a product installation elsewhere.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
VendorProductVersion
novellsuse_lifecycle_management_server
𝑥
≤ 1.3
novellsuse_lifecycle_management_server
1.0
novellsuse_lifecycle_management_server
1.1
novellsuse_lifecycle_management_server
1.2
𝑥
= Vulnerable software versions
Common Weakness Enumeration