Vulnerability Description
MailCleaner before 28d913e has default values of ssh_host_dsa_key, ssh_host_rsa_key, and ssh_host_ed25519_key that persist after installation.
CVSS Score
CRITICAL
References
- https://github.com/MailCleaner/MailCleaner/commit/28d913eaa044b689eb114f72ebe92d
- https://github.com/MailCleaner/MailCleaner/wiki/Watchdogs#host_keys
- https://www.mailcleaner.net/infobox/mc-info-box.php
FAQ
What is CVE-2024-55560?
CVE-2024-55560 is a vulnerability with a CVSS score of 9.8 (CRITICAL). MailCleaner before 28d913e has default values of ssh_host_dsa_key, ssh_host_rsa_key, and ssh_host_ed25519_key that persist after installation.
How severe is CVE-2024-55560?
CVE-2024-55560 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-55560?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.