← Back to browse · API

CVE-2025-46811

Severity
CRITICAL
CVSS
9.3
EPSS
0.10353
Risk score
40.82
CISA KEV
No
PoC
No
Published
2025-07-30
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-23155, GHSA-HRRW-RC87-QGGF
Products
SUSE:Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1 ? <5.0.27-150600.3.33.1, SUSE:Image SLES15-SP4-Manager-Server-4-3-BYOS ? <4.3.87-150400.3.110.2, SUSE:Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure ? <4.3.87-150400.3.110.2, SUSE:Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2 ? <4.3.87-150400.3.110.2, SUSE:Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE ? <4.3.87-150400.3.110.2, SUSE:SUSE Manager Server Module 4.3 ? <4.3.87-150400.3.110.2
Sources
euvd EUVD-2025-23155

Description

A Missing Authorization vulnerability in SUSE Linux Manager allows anyone with the ability to connect to port 443 of SUSE Manager is able to run any command as root on any client. This issue affects Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1: from ? before 5.0.27-150600.3.33.1; Image SLES15-SP4-Manager-Server-4-3-BYOS: from ? before 4.3.87-150400.3.110.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure: from ? before 4.3.87-150400.3.110.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2: from ? before 4.3.87-150400.3.110.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE: from ? before 4.3.87-150400.3.110.2; SUSE Manager Server Module 4.3: from ? before 4.3.87-150400.3.110.2.

References