Vulnerability Description
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sonicwall | Sma 6200 Firmware | - |
| Sonicwall | Sma 6200 | - |
| Sonicwall | Sma 7200 Firmware | - |
| Sonicwall | Sma 7200 | - |
| Arista | Eos | >= 4.32.0, <= 4.32.1f |
| Canonical | Ubuntu Linux | 23.10 |
| Almalinux | Almalinux | 9.0 |
| Sonicwall | Sma 6210 Firmware | - |
| Sonicwall | Sma 6210 | - |
| Sonicwall | Sma 7210 Firmware | - |
| Sonicwall | Sma 7210 | - |
| Sonicwall | Sma 8200V Firmware | - |
| Sonicwall | Sma 8200V | - |
| Sonicwall | Sra Ex 7000 Firmware | - |
| Sonicwall | Sra Ex 7000 | - |
| Netapp | A1K Firmware | - |
| Netapp | A1K | - |
| Netapp | A70 Firmware | - |
| Netapp | A70 | - |
| Netapp | A90 Firmware | - |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2024:4312Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:4340Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:4389Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:4469Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:4474Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:4479Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:4484Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2024-6387Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2294604Third Party Advisory
- https://santandersecurityresearch.github.io/blog/sshing_the_masses.htmlExploitThird Party Advisory
- https://www.openssh.com/txt/release-9.8Release NotesThird Party Advisory
- https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txtExploitThird Party Advisory
- http://seclists.org/fulldisclosure/2024/Jul/18Mailing List
- http://seclists.org/fulldisclosure/2024/Jul/19Mailing List
- http://seclists.org/fulldisclosure/2024/Jul/20Mailing List
FAQ
What is CVE-2024-6387?
CVE-2024-6387 is a vulnerability with a CVSS score of 8.1 (HIGH). A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote at...
How severe is CVE-2024-6387?
CVE-2024-6387 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-6387?
Check the references section above for vendor advisories and patch information. Affected products include: Sonicwall Sma 6200 Firmware, Sonicwall Sma 6200, Sonicwall Sma 7200 Firmware, Sonicwall Sma 7200, Arista Eos.