PT-2026-6354 · Go · Github.Com/Lf-Edge/Eve
Published
2026-02-04
·
Updated
2026-02-04
CVSS v3.1
5.9
Medium
| Vector | AV:P/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N |
Impact
On boot, the Pillar container checks for /config/authorized keys. If present with a valid public key, it enables SSH on port 22 with root login. The /config partition is not protected by measured boot, is mutable and unencrypted.
This enables an attacker with physical access to the device to take out the disk, modify the /config partition using a separate server, then insert it, without the inserted key being flagged as an integrity voilation my measured boot and remote attestation.
Patches
Patched in 9.4.3-lts
Workarounds
None (apart from preventing physical access to the device)
Fix
Insufficiently Protected Credentials
Insecure Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Github.Com/Lf-Edge/Eve