Medium severity6.4OSV Advisory· Published Jan 13, 2026· Updated Jul 5, 2026
CVE-2024-54855
CVE-2024-54855
Description
fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attackers to possibly execute a man-in-the-middle attack during connections with other hosts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: v1.0.2, v1.0.3, v1.1.0
- Range: =1.1.0
- Range: =1.1.0
- cpe:2.3:a:fabricators:vanilla_os_core_image:*:*:*:*:*:*:*:*Range: <1.1.1
Patches
Vulnerability mechanics
References
1- github.com/Vanilla-OS/core-image/security/advisories/GHSA-67pc-hqr2-g34hnvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.