Sept. 21, 2023, 2:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

On boot, the Pillar eve container checks for the existence and content of
“/config/authorized_keys�.

If the file is present, and contains a supported public key, the container will go on to open
port 22 and enable sshd with the given keys as the authorized keys for root login.

An attacker could easily add their own keys and gain full control over the system without
triggering the “measured boot� mechanism implemented by EVE OS, and without marking
the device as “UUDâ€� …

attacker boot container cve enable eve file key keys login open port own port public public key root

Red Team Operator

@ JPMorgan Chase & Co. | LONDON, United Kingdom

SOC Analyst

@ Resillion | Bengaluru, India

Director of Cyber Security

@ Revinate | San Francisco Bay Area

Jr. Security Incident Response Analyst

@ Kaseya | Miami, Florida, United States

Infrastructure Vulnerability Consultant - (Cloud Security , CSPM)

@ Blue Yonder | Hyderabad

Product Security Lead

@ Lely | Maassluis, Netherlands