{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_security_advisory","csaf_version":"2.1","title":"OpenSSH regreSSHion (CVE-2024-6387)","distribution":{"tlp":{"label":"CLEAR"}},"publisher":{"category":"vendor","name":"WatchGuard PSIRT","namespace":"https://www.watchguard.com"},"tracking":{"id":"WGSA-2024-00012","status":"final","version":"24","initial_release_date":"2024-07-01T12:49:53+00:00","current_release_date":"2026-07-28T02:01:25.610274+00:00","revision_history":[{"date":"2024-07-01T12:49:53+00:00","number":"24","summary":"Initial release."}]},"references":[{"summary":"vendor-advisory","url":"https://psirt.watchguard.com/WGSA-2024-00012"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2024-6387"}],"notes":[{"category":"summary","text":"*Updated August 1 2024: *\n\n\nOn July 1, Qualys [published information](https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt) about a race condition vulnerability in certain OpenSSH Server implementations when used on glibc-based linux systems. An unauthenticated attacker could exploit this vulnerability to execute arbitrary code with privileged permissions on affected systems.\n\nWatchGuard Firebox appliances use a vulnerable version of OpenSSH for the [Management Command Line Interface](https://www.watchguard.com/help/docs/fireware/12/en-US/CLI/index.html) and our initial assessment is that they affected by this vulnerability.\n\nWatchGuard Wireless Access Points do not use OpenSSH and are not affected by this vulnerability.\n\nWatchGuard Dimension uses a version of OpenSSH that is not affected by this vulnerability.","title":"Summary"}]},"product_tree":{"branches":[{"category":"vendor","name":"WatchGuard","branches":[{"category":"product_name","name":"Fireware OS (Default)","branches":[{"category":"product_version_range","name":"vers >= 12.0, < 12.10.4-b701004","product":{"name":"Fireware OS (Default) vers >= 12.0, < 12.10.4-b701004","product_id":"CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default"}}]},{"category":"product_name","name":"Secure Wi-Fi","branches":[{"category":"product_version_range","name":"all versions","product":{"name":"Secure Wi-Fi all versions","product_id":"CSAFPID-6737224d-68ea-4d9e-80e7-1f38f4c398d8"}}]},{"category":"product_name","name":"Dimension","branches":[{"category":"product_version_range","name":"all versions","product":{"name":"Dimension all versions","product_id":"CSAFPID-d36d565e-228e-4d9a-888a-9be70889d829"}}]}]}]},"vulnerabilities":[{"notes":[{"category":"description","text":"*Updated August 1 2024: *\n\n\nOn July 1, Qualys [published information](https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt) about a race condition vulnerability in certain OpenSSH Server implementations when used on glibc-based linux systems. An unauthenticated attacker could exploit this vulnerability to execute arbitrary code with privileged permissions on affected systems.\n\nWatchGuard Firebox appliances use a vulnerable version of OpenSSH for the [Management Command Line Interface](https://www.watchguard.com/help/docs/fireware/12/en-US/CLI/index.html) and our initial assessment is that they affected by this vulnerability.\n\nWatchGuard Wireless Access Points do not use OpenSSH and are not affected by this vulnerability.\n\nWatchGuard Dimension uses a version of OpenSSH that is not affected by this vulnerability.","title":"Summary"}],"product_status":{"known_affected":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default"],"known_not_affected":["CSAFPID-6737224d-68ea-4d9e-80e7-1f38f4c398d8","CSAFPID-d36d565e-228e-4d9a-888a-9be70889d829"]},"cve":"CVE-2024-6387","remediations":[{"category":"vendor_fix","details":"Upgrade to Fireware OS 12.10.4-b701004 or later.","product_ids":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default"]}]}]}