ethosdistro.com
http://ethosdistro.com/changelog CVE-2019-19755
CRITICAL
ethOS SSH Host Key Reuse
Record summary
CVE-2019-19755 has a selected CVSS score of 9.1 (critical).
Description
ethOS through 1.3.3 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: as of 2019-12-01, the vendor indicated that they plan to fix this.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 10, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 1, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
ethosBrowse ethos / ethosDefault status: unknown | CVE List | Through 1.3.3 | affected |
| VulnCheck | Version data not supplied | ||
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-19755 rsaxvc.net
https://rsaxvc.net/blog/2020/4/10/Widespread_re-use_of_SSH_Host_Keys_in_Ethereum_Mining_Rig_Operating_Systems.html