DNA View

CVE-2011-4190

Low
Low Medium High Critical
CVSS Score
Published: Jun 08, 2018
Last Modified: Nov 21, 2024

Vulnerability Description

The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific to SUSE. A remote malicious kdump server could use this flaw to impersonate the correct kdump server to obtain security sensitive information (kdump core files).

Known Affected Software

3 configuration(s) from 1 vendor(s)

suse_linux_enterprise_server
Version:
11
CPE:
cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp3:*:*:*:-:*:*
suse_linux_enterprise_server
Version:
11.0
CPE:
cpe:2.3:o:suse:suse_linux_enterprise_server:11.0:sp3:*:*:*:vmware:*:*
suse_linux_enterprise_desktop
Version:
11
CPE:
cpe:2.3:o:suse:suse_linux_enterprise_desktop:11:*:*:*:*:*:*:*
This vulnerability affects 3 software configuration(s). Ensure you patch all affected systems.

Severity Details

out of 10.0
Low

Weakness Type (CWE)

CWE-306 Top 25 #16

Missing Authentication for Critical Function

Description
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Exploit Likelihood
High
Typical Severity
High
OWASP Top 10
A07:2021-Identification/Auth Failures
Abstraction Level
Base

Key Information

Published Date
June 08, 2018