CVE-2025-30095
VyOS 1.3 through 1.5 (fixed in 1.4.2) or any Debian-based system using dropbear in combination with live-build has the same Dropbear private host keys across different installations. Thus, an attacker can conduct active man-in-the-middle attacks against SSH connections if Dropbear is enabled as the SSH daemon. I n VyOS, this is not the default configuration for the system SSH daemon, but is for the console service.
Leer descripción completaMostrar menos
To mitigate this, one can run "rm -f /etc/dropbear/*key*" and/or "rm -f /etc/dropbear-initramfs/*key*" and then dropbearkey -t rsa -s 4096 -f /etc/dropbear_rsa_host_key and reload the service or reboot the system before using Dropbear as the SSH daemon (this clears out all keys mistakenly built into the release image) or update to the latest version of VyOS 1.4 or 1.5. Note that this vulnerability is not unique to VyOS and may appear in any Debian-based Linux distribution that uses Dropbear in combination with live-build, which has a safeguard against this behavior in OpenSSH but no equivalent one for Dropbear.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Puntuación base: 9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.49%
- Percentil entre todas las CVEs puntuadas: 40
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1557Adversary-in-the-Middlecredential access · collection85 % - Impacto principal
T1041Exfiltration Over C2 Channelexfiltration80 %
Claves SSH privadas idénticas en múltiples instalaciones permiten ataques de hombre en el medio (MITM) contra conexiones SSH; AV:N, PR:N sin UI. El atacante intercepta y descifra tráfico SSH (C:H, I:H).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (2)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-321
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-30095",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-30095",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-03-31T21:08:55.093564Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve@mitre.org",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "VyOS",
"product": "VyOS",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.4.2",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.5",
"lessThan": "1.5-stream-2025-Q2",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-03-31T15:15:44.843",
"references": [
{
"url": "https://blog.vyos.io/vyos-project-march-2025-update",
"source": "cve@mitre.org"
},
{
"url": "https://blog.vyos.io/vyos-stream-1.5-2025-q1",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/vyos/",
"source": "cve@mitre.org"
},
{
"url": "https://vyos.dev/T7217",
"source": "cve@mitre.org"
},
{
"url": "https://vyos.net/get/stream/#1.5-2025-Q1",
"source": "cve@mitre.org"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "cve@mitre.org",
"description": [
{
"lang": "en",
"value": "CWE-321"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "VyOS 1.3 through 1.5 (fixed in 1.4.2) or any Debian-based system using dropbear in combination with live-build has the same Dropbear private host keys across different installations. Thus, an attacker can conduct active man-in-the-middle attacks against SSH connections if Dropbear is enabled as the SSH daemon. I n VyOS, this is not the default configuration for the system SSH daemon, but is for the console service. To mitigate this, one can run \"rm -f /etc/dropbear/*key*\" and/or \"rm -f /etc/dropbear-initramfs/*key*\" and then dropbearkey -t rsa -s 4096 -f /etc/dropbear_rsa_host_key and reload the service or reboot the system before using Dropbear as the SSH daemon (this clears out all keys mistakenly built into the release image) or update to the latest version of VyOS 1.4 or 1.5. Note that this vulnerability is not unique to VyOS and may appear in any Debian-based Linux distribution that uses Dropbear in combination with live-build, which has a safeguard against this behavior in OpenSSH but no equivalent one for Dropbear."
},
{
"lang": "es",
"value": "VyOS 1.3 a 1.5 (corregida en 1.4.2) o cualquier sistema basado en Debian que utilice dropbear en combinación con live-build tiene las mismas claves de host privadas de Dropbear en diferentes instalaciones. Por lo tanto, un atacante puede realizar ataques de intermediario activos contra conexiones SSH si Dropbear está habilitado como daemon SSH. En VyOS, esta no es la configuración predeterminada para el daemon SSH del sistema, sino para el servicio de consola. Para mitigar esto, se puede ejecutar \"rm -f /etc/dropbear/*key*\" o \"rm -f /etc/dropbear-initramfs/*key*\" y luego \"dropbearkey -t rsa -s 4096 -f /etc/dropbear_rsa_host_key\" y recargar el servicio o reiniciar el sistema antes de usar Dropbear como daemon SSH (esto borra todas las claves integradas por error en la imagen de lanzamiento) o actualizar a la última versión de VyOS 1.4 o 1.5. Tenga en cuenta que esta vulnerabilidad no es exclusiva de VyOS y puede aparecer en cualquier distribución de Linux basada en Debian que use Dropbear en combinación con live-build, que cuenta con una protección contra este comportamiento en OpenSSH, pero no con una equivalente para Dropbear."
}
],
"lastModified": "2026-06-17T09:08:09.230",
"sourceIdentifier": "cve@mitre.org"
}