← back
CVE-2019-19752criticalobserved exploitationCWE-321

CVE-2019-19752

50Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 9.8epss 0.5%
from disclosure to weapon
Published on NVDApr 30
VulnCheckApr 10
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
yesVulnCheck
nvOC through 3.2 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: as of 2019-12-01, the vendor indicated plans to fix this in the next image build.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a