Executive brief
Vanilla OS, an operating system designed for desktop and container use, was found to contain identical, pre-set security keys for its remote access (SSH) service across all installations of certain versions. Because these keys are public knowledge, an attacker could impersonate a user's computer or intercept their encrypted communications. This could lead to unauthorized access to the system or the theft of sensitive data transmitted during a remote session.
Technical details
A hard-coded cryptographic key vulnerability (CWE-321) exists in Vanilla OS core images prior to version 1.1.1. The SSH service was configured with static host keys (e.g., RSA private keys) embedded directly in the image, meaning every installation shared the same identity credentials. A network-based attacker with knowledge of these keys can perform a Man-in-the-Middle (MITM) attack to intercept SSH traffic or impersonate a legitimate server. While the CVSS vector indicates high privileges and user interaction are required, the availability of the private key in public images significantly lowers the barrier for successful interception of encrypted sessions. The issue is resolved in Core image v1.1.1 and Desktop/NVIDIA/VM images v1.1.3.
Affected products
- fabricators Ltd Vanilla OS Core Image < 1.1.1
- fabricators Ltd Vanilla OS Desktop Image < 1.1.3
- fabricators Ltd Vanilla OS NVIDIA Image < 1.1.3
- fabricators Ltd Vanilla OS VM Image < 1.1.3
Timeline
- 2025-01-13: patched: Core image v1.1.1 released to address the issue.
- 2026-01-13: advisory: Public disclosure of the vulnerability.