« Volver al listado

CVE-2025-30095

Estado: AplazadaCrítica (9)—

VyOS 1.3 through 1.5 (fixed in 1.4.2) or any Debian-based system using dropbear in combination with live-build has the same Dropbear private host keys across different installations. Thus, an attacker can conduct active man-in-the-middle attacks against SSH connections if Dropbear is enabled as the SSH daemon. I n VyOS, this is not the default configuration for the system SSH daemon, but is for the console service.

Leer descripción completaMostrar menos

To mitigate this, one can run "rm -f /etc/dropbear/*key*" and/or "rm -f /etc/dropbear-initramfs/*key*" and then dropbearkey -t rsa -s 4096 -f /etc/dropbear_rsa_host_key and reload the service or reboot the system before using Dropbear as the SSH daemon (this clears out all keys mistakenly built into the release image) or update to the latest version of VyOS 1.4 or 1.5. Note that this vulnerability is not unique to VyOS and may appear in any Debian-based Linux distribution that uses Dropbear in combination with live-build, which has a safeguard against this behavior in OpenSSH but no equivalent one for Dropbear.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Claves SSH privadas idénticas en múltiples instalaciones permiten ataques de hombre en el medio (MITM) contra conexiones SSH; AV:N, PR:N sin UI. El atacante intercepta y descifra tráfico SSH (C:H, I:H).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-30095",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-30095",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-31T21:08:55.093564Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@mitre.org",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "VyOS",
          "product": "VyOS",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.4.2",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "1.5",
              "lessThan": "1.5-stream-2025-Q2",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-03-31T15:15:44.843",
  "references": [
    {
      "url": "https://blog.vyos.io/vyos-project-march-2025-update",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://blog.vyos.io/vyos-stream-1.5-2025-q1",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/vyos/",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://vyos.dev/T7217",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://vyos.net/get/stream/#1.5-2025-Q1",
      "source": "cve@mitre.org"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@mitre.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-321"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "VyOS 1.3 through 1.5 (fixed in 1.4.2) or any Debian-based system using dropbear in combination with live-build has the same Dropbear private host keys across different installations. Thus, an attacker can conduct active man-in-the-middle attacks against SSH connections if Dropbear is enabled as the SSH daemon. I n VyOS, this is not the default configuration for the system SSH daemon, but is for the console service. To mitigate this, one can run \"rm -f /etc/dropbear/*key*\" and/or \"rm -f /etc/dropbear-initramfs/*key*\" and then dropbearkey -t rsa -s 4096 -f /etc/dropbear_rsa_host_key and reload the service or reboot the system before using Dropbear as the SSH daemon (this clears out all keys mistakenly built into the release image) or update to the latest version of VyOS 1.4 or 1.5. Note that this vulnerability is not unique to VyOS and may appear in any Debian-based Linux distribution that uses Dropbear in combination with live-build, which has a safeguard against this behavior in OpenSSH but no equivalent one for Dropbear."
    },
    {
      "lang": "es",
      "value": "VyOS 1.3 a 1.5 (corregida en 1.4.2) o cualquier sistema basado en Debian que utilice dropbear en combinación con live-build tiene las mismas claves de host privadas de Dropbear en diferentes instalaciones. Por lo tanto, un atacante puede realizar ataques de intermediario activos contra conexiones SSH si Dropbear está habilitado como daemon SSH. En VyOS, esta no es la configuración predeterminada para el daemon SSH del sistema, sino para el servicio de consola. Para mitigar esto, se puede ejecutar \"rm -f /etc/dropbear/*key*\" o \"rm -f /etc/dropbear-initramfs/*key*\" y luego \"dropbearkey -t rsa -s 4096 -f /etc/dropbear_rsa_host_key\" y recargar el servicio o reiniciar el sistema antes de usar Dropbear como daemon SSH (esto borra todas las claves integradas por error en la imagen de lanzamiento) o actualizar a la última versión de VyOS 1.4 o 1.5. Tenga en cuenta que esta vulnerabilidad no es exclusiva de VyOS y puede aparecer en cualquier distribución de Linux basada en Debian que use Dropbear en combinación con live-build, que cuenta con una protección contra este comportamiento en OpenSSH, pero no con una equivalente para Dropbear."
    }
  ],
  "lastModified": "2026-06-17T09:08:09.230",
  "sourceIdentifier": "cve@mitre.org"
}