CVE-2024-6387, dubbed "regreSSHion," is a critical race condition vulnerability in the OpenSSH server (sshd) that allows unsafe signal handling, impacting numerous Linux distributions and OpenSSH-based products. This high-severity flaw (CVSS 8.1) can be triggered remotely by an unauthenticated attacker failing to authenticate within a set time, potentially leading to full system compromise with high impact on confidentiality, integrity, and availability. The vulnerability is on the "Hot List: Active," indicating a high risk of exploitation, with public exploit code available on platforms like ExploitDB and significant community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:sonicwall:sma_6200_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:sonicwall:sma_7200_firmware:-:*:*:*:*:*:*:* | ||
>= 4.32.0, <= 4.32.1fCPE matchmatch criteria | cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* | ||
23.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:23.10:*:*:*:*:*:*:* | ||
24.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:24.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP4 Security Updates
Oct 29, 2024HP ThinPro 8.1 SP4 Security Updates
Oct 29, 2024OpenSSH Security Regression (CVE-2006-5051) Vulnerability
Jul 25, 2024OpenSSH Security Regression (CVE-2006-5051) Vulnerability
Jul 25, 2024OpenSSH Security Regression (CVE-2006-5051) Vulnerability
Jul 25, 2024OpenSSH Security Regression (CVE-2006-5051) Vulnerability
Jul 25, 2024OpenSSH Security Regression (CVE-2006-5051) Vulnerability
Jul 25, 2024OpenSSH Security Regression (CVE-2006-5051) Vulnerability
Jul 25, 2024OpenSSH Security Regression (CVE-2006-5051) Vulnerability
Jul 25, 2024OpenSSH Security Regression (CVE-2006-5051) Vulnerability
Jul 25, 2024"regreSSHion" OpenSSH vulnerability in PRC7000
Jul 19, 2024"regreSSHion" OpenSSH vulnerability in PRC7000
Jul 19, 2024"regreSSHion" OpenSSH vulnerability in PRC7000
Jul 19, 2024"regreSSHion" OpenSSH vulnerability in PRC7000
Jul 19, 2024AS-2024-004: OpenSSH
Jul 17, 2024RedHat Openssh: CVE-2024-6387 Remote Code Execution Due To A Race Condition In Signal Handling
Jul 9, 2024openssh: regreSSHion - race condition in SSH allows RCE/DoS
Jul 1, 2024Race condition resulting in potential remote code execution
Jul 1, 2024Race condition resulting in potential remote code execution.
Jul 1, 2024Race condition resulting in potential remote code execution.
Jul 1, 2024Race condition resulting in potential remote code execution.
Jul 1, 2024