---
id: CVE-2024-54855
title: >-
  fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain
  static keys for the SSH service, allowing attackers to possibly execute a
  man-in-the-middle attack during connections with other hosts.
summary: >-
  fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain
  static keys for the SSH service, allowing attackers to possibly execute a
  man-in-the-middle attack during connections with other hosts.
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:H'
cwe:
  - CWE-321
vendor: fabricators
product: vanilla_os_core_image
affected:
  - vanilla_os_core_image < 1.1.1
patched:
  - vanilla_os_core_image 1.1.1
published: '2026-01-13'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-54855'
references:
  - url: >-
      https://github.com/Vanilla-OS/core-image/security/advisories/GHSA-67pc-hqr2-g34h
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00299
epssPercentile: 0.22795
ingestedAt: '2026-07-06T16:44:34.506Z'
---

## Overview

fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attackers to possibly execute a man-in-the-middle attack during connections with other hosts.

## Affected

- `vanilla_os_core_image < 1.1.1`

## Remediation

Upgrade past the affected range:

- `vanilla_os_core_image 1.1.1`
