CVE-2024-54855 affects fabricators Ltd Vanilla OS 2 Core image v1.1.0, where it was found to contain static SSH keys. This critical flaw allows for potential man-in-the-middle attacks, compromising the integrity and confidentiality of connections. Rated 6.4 MEDIUM, the vulnerability has a high impact on confidentiality and availability, requiring high privileges and user interaction for exploitation. While not currently in the KEV catalog or having public exploit code, its high FAUCET Risk Score of 94/100 and significant community discussion (10 mentions) indicate a notable concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.1CPE matchmatch criteria | cpe:2.3:a:fabricators:vanilla_os_core_image:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.