CVE-2010-3912

critical

Description

The supportconfig script in supportutils in SUSE Linux Enterprise 11 SP1 and 10 SP3 does not "disguise passwords" in configuration files, which has unknown impact and attack vectors.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/64690

http://www.vupen.com/english/advisories/2011/0076

http://secunia.com/advisories/42877

http://osvdb.org/70405

http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.html

Details

Source: Mitre, NVD

Published: 2011-01-13

Updated: 2025-04-11

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00248