SSH Key Misconfiguration in KAS Setup Tool for Bitbake Projects by Siemens
CVE-2026-54548
3.3LOW
What is CVE-2026-54548?
The KAS setup tool, used for Bitbake-based projects, has a vulnerability prior to version 5.4 that misconfigures SSH key handling. It creates a global SSH configuration file at ~/.ssh/config without adequate user-specific checks. This configuration includes a rule that disables StrictHostKeyChecking, allowing potential man-in-the-middle attacks where an unauthorized host key could be accepted during SSH connections. As this misconfiguration persists beyond the intended environment, it poses a serious risk to session confidentiality and integrity. The issue has been addressed in version 5.4.
Affected Version(s)
kas < 5.4