CVE-2019-19752
April 30, 2024, 7:35 p.m.
Tags
Product(s) Impacted
nvOC
- 3.2
Description
nvOC through 3.2 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: as of 2019-12-01, the vendor indicated plans to fix this in the next image build.
Weaknesses
Date
Published: April 30, 2024, 6:15 p.m.
Last Modified: April 30, 2024, 7:35 p.m.
Status : Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
cve@mitre.org