HiveOS through 0.6-102@191212 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: as of 2019-09-26, the vendor indicated that they would consider fixing this.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 06 Nov 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-06T23:08:08.275Z
Reserved: 2019-12-12T00:00:00
Link: CVE-2019-19754
Updated: 2024-08-05T02:25:12.688Z
Status : Awaiting Analysis
Published: 2024-04-30T18:15:19.507
Modified: 2024-11-21T04:35:19.550
Link: CVE-2019-19754
No data.
OpenCVE Enrichment
No data.
Weaknesses