PT-2026-6354 · Go · Github.Com/Lf-Edge/Eve

Published

2026-02-04

·

Updated

2026-02-04

CVSS v3.1

5.9

Medium

VectorAV:P/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N

Impact

On boot, the Pillar container checks for /config/authorized keys. If present with a valid public key, it enables SSH on port 22 with root login. The /config partition is not protected by measured boot, is mutable and unencrypted.
This enables an attacker with physical access to the device to take out the disk, modify the /config partition using a separate server, then insert it, without the inserted key being flagged as an integrity voilation my measured boot and remote attestation.

Patches

Patched in 9.4.3-lts

Workarounds

None (apart from preventing physical access to the device)

Fix

Insufficiently Protected Credentials

Insecure Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-3MQ9-XHGQ-R7GJ

Affected Products

Github.Com/Lf-Edge/Eve