WGSA-2024-00012

OpenSSH regreSSHion (CVE-2024-6387)

Critical Published 2024-07-01Updated 2026-07-28

Summary #

*Updated August 1 2024: *

On July 1, Qualys [published information](https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt) about a race condition vulnerability in certain OpenSSH Server implementations when used on glibc-based linux systems. An unauthenticated attacker could exploit this vulnerability to execute arbitrary code with privileged permissions on affected systems.

WatchGuard Firebox appliances use a vulnerable version of OpenSSH for the [Management Command Line Interface](https://www.watchguard.com/help/docs/fireware/12/en-US/CLI/index.html) and our initial assessment is that they affected by this vulnerability.

WatchGuard Wireless Access Points do not use OpenSSH and are not affected by this vulnerability.

WatchGuard Dimension uses a version of OpenSSH that is not affected by this vulnerability.

CVE identifiers #

CVE IDDescriptionCVSS
CVE-2024-6387 A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period. 8.1

Product status #

ProductAffectedNot affected
DimensionAll versions
Fireware OS
Default >= 12.0, < 12.10.4-b701004>= 12.10.4-b701004
Secure Wi-FiAll versions

Solution #

No solution has been published for this advisory.

Workaround #

WatchGuard Firebox administrators should never expose management access, including the management CLI over SSH, to the internet or untrusted networks. See our [published guidance](https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/basicadmin/manage_firebox_remote_loc_c.html) on secure remote management options instead. Firebox administrators that do not use the management CLI over SSH can also add an explicit "Deny" firewall rule that blocks inbound TCP/4118 to the Firebox alias, placing it higher in the policy order than the default "WatchGuard" firewall management policy. WatchGuard Wi-Fi Access Point administrators should limit access to the management CLI by enabling the management VLAN on a dedicated management network.

References #