EDIT 2: TL;DR: the answer was yes in 2013, but this flaw has been fixed
By following the Getting Started instructions on vagrantup.
Just wanted to add that there is a Vagrant plugin that solves this problem:vagrant-rekey-ssh. It changes the default password of the VM, and removes the insecure SSH key.