Showing 1 vulnerability on this page for ethOS

Signals CISA KEV Ransomware Nuclei
ethosdistro vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

ethOS SSH Host Key Reuse

ethOS through 1.3.3 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: as of 2019-12-01, the vendor indicated that they plan to fix this.

CWE-300CWE-639Apr 30, 2024
CVSS9.1v3.1EPSS0.429%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX