vantage6 insecure SSH configuration for node and server containers
CVE-2024-21653

9.8CRITICAL

Key Information:

Vendor

vantage6

Status
Vendor
CVE Published:
30 January 2024

What is CVE-2024-21653?

The recent vulnerability in Vantage6 technology primarily concerns the SSH configuration that, by default, permits root login using password authentication. While optimal deployments do not expose the SSH service publicly, various configurations may inadvertently increase risk. Ensuring the integrity of sensitive operations such as Federated Learning and Multi-Party Computation necessitates more restrictive defaults. To mitigate this vulnerability effectively, it is recommended to adjust the deployment process by removing the SSH component from the Docker file and rebuilding the Docker image. Version 4.2.0 has been released which addresses this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

vantage6 < 4.2.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.