CVE-2024-6387
HIGHDescription
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| sonicwall | sma_6200_firmware |
| sonicwall | sma_6200 |
| sonicwall | sma_7200_firmware |
| sonicwall | sma_7200 |
| arista | eos |
| canonical | ubuntu_linux |
| canonical | ubuntu_linux |
| almalinux | almalinux |
| sonicwall | sma_6210_firmware |
| sonicwall | sma_6210 |
| sonicwall | sma_7210_firmware |
| sonicwall | sma_7210 |
| sonicwall | sma_8200v_firmware |
| sonicwall | sma_8200v |
| sonicwall | sra_ex_7000_firmware |
| sonicwall | sra_ex_7000 |
| netapp | a1k_firmware |
| netapp | a1k |
| netapp | a70_firmware |
| netapp | a70 |
| netapp | a90_firmware |
| netapp | a90 |
| netapp | a700s_firmware |
| netapp | a700s |
| netapp | 8300_firmware |
| netapp | 8300 |
| netapp | 8700_firmware |
| netapp | 8700 |
| netapp | a400_firmware |
| netapp | a400 |
| netapp | c400_firmware |
| netapp | c400 |
| netapp | a250_firmware |
| netapp | a250 |
| netapp | 500f_firmware |
| netapp | 500f |
| netapp | c250_firmware |
| netapp | c250 |
| netapp | a800_firmware |
| netapp | a800 |
| netapp | c800_firmware |
| netapp | c800 |
| netapp | a900_firmware |
| netapp | a900 |
| netapp | a9500_firmware |
| netapp | a9500 |
| netapp | c190_firmware |
| netapp | c190 |
| netapp | a150_firmware |
| netapp | a150 |
| netapp | a220_firmware |
| netapp | a220 |
| netapp | fas2720_firmware |
| netapp | fas2720 |
| netapp | fas2750_firmware |
| netapp | fas2750 |
| netapp | fas2820_firmware |
| netapp | fas2820 |
| netapp | bootstrap_os |
| netapp | hci_compute_node |
| apple | macos |
| apple | macos |
| apple | macos |
| openbsd | openssh |
| openbsd | openssh |
| openbsd | openssh |
| openbsd | openssh |
| openbsd | openssh |
| redhat | openshift_container_platform |
| redhat | enterprise_linux |
| redhat | enterprise_linux_eus |
| redhat | enterprise_linux_for_arm_64 |
| redhat | enterprise_linux_for_arm_64_eus |
| redhat | enterprise_linux_for_ibm_z_systems |
| redhat | enterprise_linux_for_ibm_z_systems_eus |
| redhat | enterprise_linux_for_power_little_endian |
| redhat | enterprise_linux_for_power_little_endian_eus |
| redhat | enterprise_linux_server_aus |
| suse | linux_enterprise_micro |
| debian | debian_linux |
| canonical | ubuntu_linux |
| canonical | ubuntu_linux |
| canonical | ubuntu_linux |
| amazon | amazon_linux |
| netapp | active_iq_unified_manager |
| netapp | e-series_santricity_os_controller |
| netapp | ontap |
| netapp | ontap_select_deploy_administration_utility |
| netapp | ontap_tools |
| netapp | ontap_tools |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| freebsd | freebsd |
| netbsd | netbsd |
References
Advisories & Patches
Exploits
Other References
Frequently Asked Questions
What is CVE-2024-6387? +
How severe is CVE-2024-6387? +
What products are affected by CVE-2024-6387? +
How do I check if I'm vulnerable to CVE-2024-6387? +
Related Vulnerabilities
in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.
A signal handler in sshd(8) may call a logging function that is not async-signal-safe. The signal handler is invoked when …
A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does …
Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfiguration vulnerability in …
Concurrency and locking defects in GSS-TSIG
in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak.