OpenSSH regreSSHion (CVE-2024-6387)
Summary #
*Updated August 1 2024: *
On July 1, Qualys [published information](https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt) about a race condition vulnerability in certain OpenSSH Server implementations when used on glibc-based linux systems. An unauthenticated attacker could exploit this vulnerability to execute arbitrary code with privileged permissions on affected systems.
WatchGuard Firebox appliances use a vulnerable version of OpenSSH for the [Management Command Line Interface](https://www.watchguard.com/help/docs/fireware/12/en-US/CLI/index.html) and our initial assessment is that they affected by this vulnerability.
WatchGuard Wireless Access Points do not use OpenSSH and are not affected by this vulnerability.
WatchGuard Dimension uses a version of OpenSSH that is not affected by this vulnerability.
CVE identifiers #
| CVE ID | Description | CVSS |
|---|---|---|
| CVE-2024-6387 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period. | 8.1 |
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Dimension | — | All versions |
| Fireware OS | ||
| Default | >= 12.0, < 12.10.4-b701004 | >= 12.10.4-b701004 |
| Secure Wi-Fi | — | All versions |
Solution #
No solution has been published for this advisory.