CVE-2019-19755
EUVD-2019-935530.04.2024, 18:15
ethOS through 1.3.3 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: as of 2019-12-01, the vendor indicated that they plan to fix this.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| ethos | ethos | 𝑥 ≤ 1.3.3 | ADP |
Common Weakness Enumeration
References