cisco-sa-openssh-rce-2024: Remote Unauthenticated Code Execution Vulnerability in OpenSSH Server (regreSSHion): July 2024
Published Jul 2, 2024
·Updated
On July 1, 2024, the Qualys Threat Research Unit (TRU) disclosed an unauthenticated, remote code execution vulnerability that affects the OpenSSH server (sshd) in glibc-based Linux systems.CVE-2024-6387: A signal handler race condition was found in sshd, where a
Affected Software
1 affected component
OpenSSH OpenSSH Server
Event History
Jul 2, 2024
Advisory Published
via Cisco·04:00 PM
Data Sourced
via Cisco·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of cisco-sa-openssh-rce-2024?
The severity of cisco-sa-openssh-rce-2024 is critical due to its remote code execution capability.
2
How do I fix cisco-sa-openssh-rce-2024?
To fix cisco-sa-openssh-rce-2024, users should apply the latest security patches or updates provided by their Linux distribution vendor.
3
What systems are affected by cisco-sa-openssh-rce-2024?
cisco-sa-openssh-rce-2024 affects glibc-based Linux systems running the OpenSSH server.
4
What type of vulnerability is cisco-sa-openssh-rce-2024?
cisco-sa-openssh-rce-2024 is an unauthenticated remote code execution vulnerability.
5
When was cisco-sa-openssh-rce-2024 disclosed?
cisco-sa-openssh-rce-2024 was disclosed on July 1, 2024.