CVE-2019-19752

nvOC through 3.2 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: as of 2019-12-01, the vendor indicated plans to fix this in the next image build.
Configurations

No configuration.

History

25 Mar 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-321

Information

Published : 2024-04-30 18:15

Updated : 2025-03-25 19:15


NVD link : CVE-2019-19752

Mitre link : CVE-2019-19752

CVE.ORG link : CVE-2019-19752


JSON object : View

Products Affected

No product.

CWE
CWE-321

Use of Hard-coded Cryptographic Key