CVE-2024-6387

Modified
Published: 01 Jul 2024, 12:37
Last modified:12 May 2026, 11:39

Vulnerability Summary

Overall Risk (default)
high
55/100
CVSS Score
8.1 HIGH
v3.1 (cve.org)
EPSS Score
63.83% CRITICAL
64% probability +37.96%
KEV
Not listed
Ransomware
No reports
Public exploits
9 found
Dark Web
Not detected

Timeline

01 Jul 2024, 12:37
Published
Vulnerability first disclosed
12 May 2026, 11:39
Last Modified
Vulnerability information updated

Description

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

CVSS Metrics

  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 63.83% Percentile: 98%

Techniques & Countermeasures

  • CWE-364Signal Handler Race Condition

    The product uses a signal handler that introduces a race condition.

  • CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

    The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Affected Systems

  • almalinuxalmalinux

    9.0

  • amazonamazon_linux

    2023.0

  • UnknownmacOS

    ≥ 12.0, < 12.7.6 | ≥ 13.0, < 13.6.8 | ≥ 14.0, < 14.6

  • aristaeos

    ≥ 4.32.0, ≤ 4.32.1f

  • canonicalubuntu_linux

    23.10 | 24.04 | 22.04 | 22.10 | 23.04

  • debiandebian_linux

    12.0

  • freebsdfreebsd

    13.2 | 13.2:p1 | 13.2:p10 | 13.2:p11 | 13.2:p2 | 13.2:p3 | 13.2:p4 | 13.2:p5 | 13.2:p6 | 13.2:p7 | 13.2:p8 | 13.2:p9 | 13.3 | 13.3:p1 | 13.3:p2 | 13.3:p3 | 14.0 | 14.0:beta5 | 14.0:p1 | 14.0:p2 | 14.0:p3 | 14.0:p4 | 14.0:p5 | 14.0:p6 | 14.0:p7 | 14.0:rc3 | 14.0:rc4-p1 | 14.1 | 14.1:p1

  • netapp500f_firmware

    na

  • netapp8300_firmware

    na

  • netapp8700_firmware

    na

  • netappa150_firmware

    na

  • netappa1k_firmware

    na

  • netappa220_firmware

    na

  • netappa250_firmware

    na

  • netappa400_firmware

    na

  • netappa70_firmware

    na

  • netappa700s_firmware

    na

  • netappa800_firmware

    na

  • netappa90_firmware

    na

  • netappa900_firmware

    na

  • netappa9500_firmware

    na

  • netappactive_iq_unified_manager

    na

  • netappbootstrap_os

    na

  • netappc190_firmware

    na

  • netappc250_firmware

    na

  • netappc400_firmware

    na

  • netappc800_firmware

    na

  • netappe-series_santricity_os_controller

    ≥ 11.0.0, ≤ 11.70.2

  • netappfas2720_firmware

    na

  • netappfas2750_firmware

    na

  • netappfas2820_firmware

    na

  • netappontap

    9

  • netappontap_select_deploy_administration_utility

    na

  • netappontap_tools

    9 | 10

  • netbsdnetbsd

    ≤ 10.0.0

  • openbsdopenssh

    < 4.4 | ≥ 8.6, ≤ 9.8 | 4.4 | 8.5:p1 | 8.6

  • redhatenterprise_linux

    9.0

  • redhatenterprise_linux_eus

    9.4

  • redhatenterprise_linux_for_arm_64

    9.0_aarch64

  • redhatenterprise_linux_for_arm_64_eus

    9.4_aarch64

  • redhatenterprise_linux_for_ibm_z_systems

    9.0_s390x

  • redhatenterprise_linux_for_ibm_z_systems_eus

    9.4_s390x

  • redhatenterprise_linux_for_power_little_endian

    9.0_ppc64le

  • redhatenterprise_linux_for_power_little_endian_eus

    9.4_ppc64le

  • redhatenterprise_linux_server_aus

    9.4

  • redhatopenshift_container_platform

    4.0

  • sonicwallsma_6200_firmware

    na

  • sonicwallsma_6210_firmware

    na

  • sonicwallsma_7200_firmware

    na

  • sonicwallsma_7210_firmware

    na

Showing first 50 affected entries in server-rendered view.

References (81)