CVE-2025-30234

high

Description

SmartOS, as used in Triton Data Center and other products, has static host SSH keys in the 60f76fd2-143f-4f57-819b-1ae32684e81b image (a Debian 12 LX zone image from 2024-07-26).

References

https://www.openwall.com/lists/oss-security/2025/03/13/10

https://smartos.topicbox.com/groups/smartos-discuss/Ta6f13072e6bedddc-M3702e993edd7d6ce8d78dfc8

https://security.tritondatacenter.com/tps-2025-002/

Details

Source: Mitre, NVD

Published: 2025-03-19

Updated: 2025-03-19

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:A/AC:H/Au:N/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 8.3

Vector: CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00029