Vulnerabilities > Opensuse > Cryptctl > 2.0

DATE CVE VULNERABILITY TITLE RISK
2021-06-30 CVE-2019-18906 Improper Authentication vulnerability in Opensuse Cryptctl
A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server 4.0 allows attackers with access to the hashed password to use it without having to crack it.
network
low complexity
opensuse CWE-287
critical
9.8
2018-03-01 CVE-2017-9270 Improper Input Validation vulnerability in Opensuse Cryptctl 2.0
In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files outside of the cryptctl key database.
network
low complexity
opensuse CWE-20
critical
9.1