SSH Key Misconfiguration in KAS Setup Tool for Bitbake Projects by Siemens
CVE-2026-54548

3.3LOW

Key Information:

Vendor

Siemens

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-54548?

The KAS setup tool, used for Bitbake-based projects, has a vulnerability prior to version 5.4 that misconfigures SSH key handling. It creates a global SSH configuration file at ~/.ssh/config without adequate user-specific checks. This configuration includes a rule that disables StrictHostKeyChecking, allowing potential man-in-the-middle attacks where an unauthorized host key could be accepted during SSH connections. As this misconfiguration persists beyond the intended environment, it poses a serious risk to session confidentiality and integrity. The issue has been addressed in version 5.4.

Affected Version(s)

kas < 5.4

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.