CVE-2024-6409 is a race condition vulnerability in OpenSSH's server (sshd) that can lead to remote code execution (RCE) as an unprivileged user. This occurs when an unauthenticated remote attacker triggers sshd's SIGALRM handler, which then calls non-async-signal-safe functions. With a CVSS score of 7.0 (HIGH) and a high EPSS score, this vulnerability presents a significant risk due to its network-based attack vector and high impact on confidentiality, integrity, and availability. While there is no public exploit code or active exploitation reported, the vulnerability has garnered community attention and media coverage, indicating a potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 9 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat OpenShift Container Platform 4.13 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat OpenShift Container Platform 4.14 | Range not provided by sourceCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.