PT-2024-10728 · Hiveos · Hiveos

Published

2024-04-30

·

Updated

2024-11-06

·

CVE-2019-19754

CVSS v3.1

5.7

Medium

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HiveOS versions 0.6-102@191212 and earlier
Description The issue allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io, as SSH host keys are baked into the installation image. The vendor indicated that they would consider fixing this as of 2019-09-26.
Recommendations For HiveOS versions 0.6-102@191212 and earlier, consider regenerating SSH host keys to prevent man-in-the-middle attacks. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Weakness Enumeration

Related Identifiers

CVE-2019-19754

Affected Products

Hiveos