SSH as Root Unlockable Without Triggering Measured Boot
CVE-2023-43631
What is CVE-2023-43631?
The EVE OS by Zededa is susceptible to a vulnerability where unauthorized SSH access can be gained through the '/config/authorized_keys' file. If this file contains a supported public key at boot, it enables SSH with root login without requiring changes to the device's PCR values, undermining the 'measured boot' mechanism. The '/config' partition, being mutable and unprotected, allows attackers to insert malicious keys, providing complete control over the system without detection. This issue arose due to changes in the handling of configuration measurements in version 9.0.0, leaving critical security features ineffective.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EVE OS 0 < 8.6.0
EVE OS 9.0.0 < 9.5.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
