CVE-2024-54855

fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attackers to possibly execute a man-in-the-middle attack during connections with other hosts.
Configurations

Configuration 1 (hide)

cpe:2.3:a:fabricators:vanilla_os_core_image:*:*:*:*:*:*:*:*

History

05 Jul 2026, 17:17

Type Values Removed Values Added
References
  • {'url': 'http://fabricators.com', 'tags': ['Broken Link'], 'source': 'cve@mitre.org'}

05 Jul 2026, 02:16

Type Values Removed Values Added
References
  • {'url': 'http://vanilla.com', 'tags': ['Not Applicable'], 'source': 'cve@mitre.org'}

17 Jun 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) La imagen v1.1.0 de fabricators Ltd Vanilla OS 2 Core se descubrió que contenía claves estáticas para el servicio SSH, lo que podría permitir a los atacantes ejecutar un ataque man-in-the-middle durante las conexiones con otros hosts.

10 Feb 2026, 18:36

Type Values Removed Values Added
References () http://fabricators.com - () http://fabricators.com - Broken Link
References () http://vanilla.com - () http://vanilla.com - Not Applicable
References () https://github.com/Vanilla-OS/core-image/security/advisories/GHSA-67pc-hqr2-g34h - () https://github.com/Vanilla-OS/core-image/security/advisories/GHSA-67pc-hqr2-g34h - Exploit, Vendor Advisory
First Time Fabricators
Fabricators vanilla Os Core Image
CPE cpe:2.3:a:fabricators:vanilla_os_core_image:*:*:*:*:*:*:*:*

13 Jan 2026, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 16:15

Updated : 2026-07-05 17:17


NVD link : CVE-2024-54855

Mitre link : CVE-2024-54855

CVE.ORG link : CVE-2024-54855


JSON object : View

Products Affected

fabricators

  • vanilla_os_core_image
CWE
CWE-321

Use of Hard-coded Cryptographic Key