CVE-2024-54855

fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attackers to possibly execute a man-in-the-middle attack during connections with other hosts.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:fabricators:vanilla_os_core_image:*:*:*:*:*:*:*:*

History

10 Feb 2026, 18:36

Type Values Removed Values Added
References () http://fabricators.com - () http://fabricators.com - Broken Link
References () http://vanilla.com - () http://vanilla.com - Not Applicable
References () https://github.com/Vanilla-OS/core-image/security/advisories/GHSA-67pc-hqr2-g34h - () https://github.com/Vanilla-OS/core-image/security/advisories/GHSA-67pc-hqr2-g34h - Exploit, Vendor Advisory
First Time Fabricators
Fabricators vanilla Os Core Image
CPE cpe:2.3:a:fabricators:vanilla_os_core_image:*:*:*:*:*:*:*:*

13 Jan 2026, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 16:15

Updated : 2026-02-10 18:36


NVD link : CVE-2024-54855

Mitre link : CVE-2024-54855

CVE.ORG link : CVE-2024-54855


JSON object : View

Products Affected

fabricators

  • vanilla_os_core_image
CWE
CWE-321

Use of Hard-coded Cryptographic Key