blog.easymine.io
https://blog.easymine.io/ CVE-2019-19751
MEDIUM
easyMINE SSH Host Key Reuse
Record summary
CVE-2019-19751 has a selected CVSS score of 5.6 (medium).
Description
easyMINE before 2019-12-05 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 10, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 1, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
easyMINEBrowse easyMINE / easyMINEDefault status: unknown | VulnCheck, CVE List | 2019-12-05 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-19751 rsaxvc.net
https://rsaxvc.net/blog/2020/4/10/Widespread_re-use_of_SSH_Host_Keys_in_Ethereum_Mining_Rig_Operating_Systems.html