PT-2024-10854 · Minerbabe · Minerbabe

Published

2024-04-30

·

Updated

2024-11-04

·

CVE-2020-5200

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Minerbabe versions through V4.16
Description The issue allows man-in-the-middle attacks due to SSH host keys being baked into the installation image. This makes it trivial to identify all public IPv4 nodes using Shodan.io.
Recommendations For Minerbabe versions through V4.16, consider regenerating SSH host keys to prevent man-in-the-middle attacks. As a temporary workaround, restrict access to the affected nodes to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2020-5200

Affected Products

Minerbabe