{"id":"CVE-2024-54855","title":"fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attackers to possibly execute a man-in-the-middle attack during connections with other hosts.","summary":"fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attackers to possibly execute a man-in-the-middle attack during connections with other hosts.","severity":"medium","cvss":6.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:H","cwe":["CWE-321"],"vendor":"fabricators","product":"vanilla_os_core_image","affected":["vanilla_os_core_image < 1.1.1"],"patched":["vanilla_os_core_image 1.1.1"],"published":"2026-01-13","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-54855","references":[{"url":"https://github.com/Vanilla-OS/core-image/security/advisories/GHSA-67pc-hqr2-g34h","label":"cve@mitre.org"}],"tags":["nvd"],"epss":0.00299,"epssPercentile":0.22791,"ingestedAt":"2026-07-06T16:44:34.506Z","slug":"CVE-2024-54855","body":"## Overview\n\nfabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attackers to possibly execute a man-in-the-middle attack during connections with other hosts.\n\n## Affected\n\n- `vanilla_os_core_image < 1.1.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `vanilla_os_core_image 1.1.1`","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":35.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}