CVE-2019-18906: Opensuse Cryptctl

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server 4.0 allows attackers with access to the hashed password to use it without having to crack it. This issue affects: SUSE Linux Enterprise Server for SAP 12-SP5 cryptctl versions prior to 2.4. SUSE Manager Server 4.0 cryptctl versions prior to 2.4.

Affected products

  • Opensuse Cryptctl: before 2.4 (fixed in 2.4)

Published 2021-06-30. Last modified 2026-06-17.