Description Preview
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). This vulnerability arises from a race condition that can lead sshd to handle certain signals in an unsafe manner. An unauthenticated, remote attacker may exploit this vulnerability by failing to authenticate within a specified time period, which could result in remote code execution (RCE) or denial of service (DoS). The vulnerability affects OpenSSH versions from 8.5p1 up to 9.7p1, and it has been classified with a CVSS base score of 8.1, indicating a high severity level.
Overview
- CVE ID: CVE-2024-6387
- Published Date: July 1, 2024
- Severity: High (CVSS Score: 8.1)
- Attack Vector: Network
- Impact: High impact on confidentiality, integrity, and availability
- Affected Versions: OpenSSH versions 8.5p1 to 9.7p1
- Vulnerability Type: Signal Handler Race Condition (CWE-364)
Remediation
To mitigate the risk associated with CVE-2024-6387, it is recommended to:
- Update OpenSSH to a version that is not affected by this vulnerability (e.g., versions beyond 9.7p1).
- As a temporary workaround, disable the
LoginGraceTime
parameter in the SSH daemon configuration:- Open the
/etc/ssh/sshd_config
file as the root user. - Add or edit the following line:
LoginGraceTime 0
- Save and close the file.
- Restart the SSH daemon with:
systemctl restart sshd.service
LoginGraceTime
may expose the server to denial of service attacks if an attacker exhausts all connections. It is advisable to use additional security measures, such asfail2ban
, to monitor connections. - Open the
References
- Red Hat Security Advisory RHSA-2024:4312
- Red Hat Security Advisory RHSA-2024:4340
- Red Hat Security Advisory RHSA-2024:4389
- Red Hat Security Advisory RHSA-2024:4469
- Red Hat Security Advisory RHSA-2024:4474
- Red Hat Security Advisory RHSA-2024:4479
- Red Hat Security Advisory RHSA-2024:4484
- CVE-2024-6387 on Red Hat
- Bugzilla Report RHBZ#2294604
- Qualys Blog on CVE-2024-6387
- OpenSSH Release Notes
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- Public AdministrationPublic Administration: Medium
- ManufacturingManufacturing: Medium
- Health Care & Social AssistanceHealth Care & Social Assistance: Medium
- Educational ServicesEducational Services: Medium
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services: Medium
- Finance and InsuranceFinance and Insurance: Medium
- Transportation & WarehousingTransportation & Warehousing: Medium
- Retail TradeRetail Trade: Medium
- UtilitiesUtilities: Medium
- Other Services (except Public Administration)Other Services (except Public Administration): Medium
- Arts, Entertainment & RecreationArts, Entertainment & Recreation: Low
- InformationInformation: Low
- Management of Companies & EnterprisesManagement of Companies & Enterprises: Low
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting: Low
- Accommodation & Food ServicesAccommodation & Food Services: Low
- MiningMining: Low
- ConstructionConstruction: Low
- Real Estate Rental & LeasingReal Estate Rental & Leasing: Low
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services: Low
- Wholesale TradeWholesale Trade: Low