CVE-2024-6387
גבוהה 8.1
תיאור (מקור, אנגלית)
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
מדדים
- CVSS 3.1
-
8.1 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-18/9/2026
- CWE
- CWE-364, CWE-362
מוצרים מושפעים
sonicwall: sma 6200 firmware; sonicwall: sma 6200; sonicwall: sma 7200 firmware; sonicwall: sma 7200; arista: eos; canonical: ubuntu linux; almalinux: almalinux; sonicwall: sma 6210 firmware; sonicwall: sma 6210; sonicwall: sma 7210 firmware; sonicwall: sma 7210; sonicwall: sma 8200v firmware; sonicwall: sma 8200v; sonicwall: sra ex 7000 firmware; sonicwall: sra ex 7000
קישורים
- http://www.openwall.com/lists/oss-security/2024/07/03/3 Mailing ListPatch
- https://github.com/openela-main/openssh/commit/e1f438970e5a337a17070a637c1b9e1… Patch
- https://lists.mindrot.org/pipermail/openssh-unix-dev/2024-July/041431.html Mailing ListPatch
- https://news.ycombinator.com/item?id=40843778 Issue TrackingPatch
- https://santandersecurityresearch.github.io/blog/sshing_the_masses.html ExploitThird Party Advisory
- https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt ExploitThird Party Advisory
- http://www.openwall.com/lists/oss-security/2024/07/03/11 ExploitMailing List
- http://www.openwall.com/lists/oss-security/2024/07/04/2 ExploitMailing List
- http://www.openwall.com/lists/oss-security/2024/07/08/2 ExploitMailing List
- http://www.openwall.com/lists/oss-security/2024/07/09/5 ExploitMailing List