CVE-2024-6387

Published Jul 1, 2024

Last updated a month ago

Modified

Description

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

Insights

Analysis from the Intruder Security Team Published Oct 15, 2024

This vulnerability affects OpenSSH and could allow an attacker to execute commands on an affected device. The vulnerability is highly complex and has limitations which is likely to prevent widespread exploitation.

More information is available in our blog post here.

Risk scores

CVSS 3.1

Primary
8.1
5.9
2.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
HIGH

Weaknesses

CWE-362
CWE-364

Source

secalert@redhat.com

Configurations