8.1
CVE-2024-6387
- EPSS 38.58%
- Published 01.07.2024 13:15:06
- Last modified 30.09.2025 13:52:23
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
Data is provided by the National Vulnerability Database (NVD)
Sonicwall ≫ Sma 6200 Firmware Version-
Sonicwall ≫ Sma 7200 Firmware Version-
Canonical ≫ Ubuntu Linux Version23.10
Canonical ≫ Ubuntu Linux Version24.04 SwEditionlts
Sonicwall ≫ Sma 6210 Firmware Version-
Sonicwall ≫ Sma 7210 Firmware Version-
Sonicwall ≫ Sma 8200v Firmware Version-
Sonicwall ≫ Sra Ex 7000 Firmware Version-
Netapp ≫ A1k Firmware Version-
Netapp ≫ A70 Firmware Version-
Netapp ≫ A90 Firmware Version-
Netapp ≫ A700s Firmware Version-
Netapp ≫ 8300 Firmware Version-
Netapp ≫ 8700 Firmware Version-
Netapp ≫ A400 Firmware Version-
Netapp ≫ C400 Firmware Version-
Netapp ≫ A250 Firmware Version-
Netapp ≫ 500f Firmware Version-
Netapp ≫ C250 Firmware Version-
Netapp ≫ A800 Firmware Version-
Netapp ≫ C800 Firmware Version-
Netapp ≫ A900 Firmware Version-
Netapp ≫ A9500 Firmware Version-
Netapp ≫ C190 Firmware Version-
Netapp ≫ A150 Firmware Version-
Netapp ≫ A220 Firmware Version-
Netapp ≫ Fas2720 Firmware Version-
Netapp ≫ Fas2750 Firmware Version-
Netapp ≫ Fas2820 Firmware Version-
Netapp ≫ Bootstrap Os Version-
Redhat ≫ Openshift Container Platform Version4.0
Redhat ≫ Enterprise Linux Version9.0
Redhat ≫ Enterprise Linux Eus Version9.4
Redhat ≫ Enterprise Linux For Arm 64 Version9.0_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version9.4_aarch64
Redhat ≫ Enterprise Linux For Ibm Z Systems Version9.0_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version9.4_s390x
Redhat ≫ Enterprise Linux For Power Little Endian Version9.0_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version9.4_ppc64le
Redhat ≫ Enterprise Linux Server Aus Version9.4
Suse ≫ Linux Enterprise Micro Version6.0
Debian ≫ Debian Linux Version12.0
Canonical ≫ Ubuntu Linux Version22.04 SwEditionlts
Canonical ≫ Ubuntu Linux Version22.10 SwEdition-
Canonical ≫ Ubuntu Linux Version23.04 SwEditionlts
Amazon ≫ Amazon Linux Version2023.0
Netapp ≫ Active Iq Unified Manager Version- SwPlatformvmware_vsphere
Netapp ≫ E-series Santricity Os Controller Version >= 11.0.0 <= 11.70.2
Netapp ≫ Ontap Select Deploy Administration Utility Version-
Netapp ≫ Ontap Tools Version9 SwPlatformvmware_vsphere
Netapp ≫ Ontap Tools Version10 SwPlatformvmware_vsphere
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 38.58% | 0.971 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
secalert@redhat.com | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
CWE-364 Signal Handler Race Condition
The product uses a signal handler that introduces a race condition.