CVE-2019-19755

ethOS through 1.3.3 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: as of 2019-12-01, the vendor indicated that they plan to fix this.
Configurations

No configuration.

History

No history.

Information

Published : 2024-04-30 18:15

Updated : 2024-11-21 04:35


NVD link : CVE-2019-19755

Mitre link : CVE-2019-19755

CVE.ORG link : CVE-2019-19755


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key