HIGH · 8.1

CVE-2024-6387

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote at...

Vulnerability Description

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

CVSS Score

8.1

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SonicwallSma 6200 Firmware-
SonicwallSma 6200-
SonicwallSma 7200 Firmware-
SonicwallSma 7200-
AristaEos>= 4.32.0, <= 4.32.1f
CanonicalUbuntu Linux23.10
AlmalinuxAlmalinux9.0
SonicwallSma 6210 Firmware-
SonicwallSma 6210-
SonicwallSma 7210 Firmware-
SonicwallSma 7210-
SonicwallSma 8200V Firmware-
SonicwallSma 8200V-
SonicwallSra Ex 7000 Firmware-
SonicwallSra Ex 7000-
NetappA1K Firmware-
NetappA1K-
NetappA70 Firmware-
NetappA70-
NetappA90 Firmware-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-6387?

CVE-2024-6387 is a vulnerability with a CVSS score of 8.1 (HIGH). A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote at...

How severe is CVE-2024-6387?

CVE-2024-6387 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-6387?

Check the references section above for vendor advisories and patch information. Affected products include: Sonicwall Sma 6200 Firmware, Sonicwall Sma 6200, Sonicwall Sma 7200 Firmware, Sonicwall Sma 7200, Arista Eos.