CVE Feed

    Dashboard / CVE / CVE-2024-6387

    CVE-2024-6387

    A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

    Published:Jul 1, 2024
    Last Modified:Aug 31, 2026
    EPS:Jul 1, 2024
    EPSS Score:0.99506
    CVSS Score:8.1

    Affected Products

    Vendor
    Almalinux
    Product
    Almalinux
    Vendor
    Amazon
    Product
    Amazon Linux
    Vendor
    Apple
    Product
    Macos
    Vendor
    Arista
    Product
    Eos
    Vendor
    Canonical
    Product
    Ubuntu Linux
    Vendor
    Debian
    Product
    Debian Linux
    Vendor
    Freebsd
    Product
    Freebsd
    Vendor
    Netapp
    Product
    500f
    Vendor
    Netapp
    Product
    500f Firmware
    Vendor
    Netapp
    Product
    8300
    Vendor
    Netapp
    Product
    8300 Firmware
    Vendor
    Netapp
    Product
    8700
    Vendor
    Netapp
    Product
    8700 Firmware
    Vendor
    Netapp
    Product
    A150
    Vendor
    Netapp
    Product
    A150 Firmware
    Vendor
    Netapp
    Product
    A1k
    Vendor
    Netapp
    Product
    A1k Firmware
    Vendor
    Netapp
    Product
    A220
    Vendor
    Netapp
    Product
    A220 Firmware
    Vendor
    Netapp
    Product
    A250
    Vendor
    Netapp
    Product
    A250 Firmware
    Vendor
    Netapp
    Product
    A400
    Vendor
    Netapp
    Product
    A400 Firmware
    Vendor
    Netapp
    Product
    A70
    Vendor
    Netapp
    Product
    A700s
    Vendor
    Netapp
    Product
    A700s Firmware
    Vendor
    Netapp
    Product
    A70 Firmware
    Vendor
    Netapp
    Product
    A800
    Vendor
    Netapp
    Product
    A800 Firmware
    Vendor
    Netapp
    Product
    A90
    Vendor
    Netapp
    Product
    A900
    Vendor
    Netapp
    Product
    A900 Firmware
    Vendor
    Netapp
    Product
    A90 Firmware
    Vendor
    Netapp
    Product
    A9500
    Vendor
    Netapp
    Product
    A9500 Firmware
    Vendor
    Netapp
    Product
    Active Iq Unified Manager
    Vendor
    Netapp
    Product
    Bootstrap Os
    Vendor
    Netapp
    Product
    C190
    Vendor
    Netapp
    Product
    C190 Firmware
    Vendor
    Netapp
    Product
    C250
    Vendor
    Netapp
    Product
    C250 Firmware
    Vendor
    Netapp
    Product
    C400
    Vendor
    Netapp
    Product
    C400 Firmware
    Vendor
    Netapp
    Product
    C800
    Vendor
    Netapp
    Product
    C800 Firmware
    Vendor
    Netapp
    Product
    E-series Santricity Os Controller
    Vendor
    Netapp
    Product
    Fas2720
    Vendor
    Netapp
    Product
    Fas2720 Firmware
    Vendor
    Netapp
    Product
    Fas2750
    Vendor
    Netapp
    Product
    Fas2750 Firmware
    Vendor
    Netapp
    Product
    Fas2820
    Vendor
    Netapp
    Product
    Fas2820 Firmware
    Vendor
    Netapp
    Product
    Hci Compute Node
    Vendor
    Netapp
    Product
    Ontap
    Vendor
    Netapp
    Product
    Ontap Select Deploy Administration Utility
    Vendor
    Netapp
    Product
    Ontap Tools
    Vendor
    Netbsd
    Product
    Netbsd
    Vendor
    Openbsd
    Product
    Openssh
    Vendor
    Redhat
    Product
    Ceph Storage
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Enterprise Linux Eus
    Vendor
    Redhat
    Product
    Enterprise Linux For Arm 64
    Vendor
    Redhat
    Product
    Enterprise Linux For Arm 64 Eus
    Vendor
    Redhat
    Product
    Enterprise Linux For Ibm Z Systems
    Vendor
    Redhat
    Product
    Enterprise Linux For Ibm Z Systems Eus
    Vendor
    Redhat
    Product
    Enterprise Linux For Power Little Endian
    Vendor
    Redhat
    Product
    Enterprise Linux For Power Little Endian Eus
    Vendor
    Redhat
    Product
    Enterprise Linux Server Aus
    Vendor
    Redhat
    Product
    Openshift
    Vendor
    Redhat
    Product
    Openshift Container Platform
    Vendor
    Redhat
    Product
    Rhel E4s
    Vendor
    Redhat
    Product
    Rhel Eus
    Vendor
    Sonicwall
    Product
    Sma 6200
    Vendor
    Sonicwall
    Product
    Sma 6200 Firmware
    Vendor
    Sonicwall
    Product
    Sma 6210
    Vendor
    Sonicwall
    Product
    Sma 6210 Firmware
    Vendor
    Sonicwall
    Product
    Sma 7200
    Vendor
    Sonicwall
    Product
    Sma 7200 Firmware
    Vendor
    Sonicwall
    Product
    Sma 7210
    Vendor
    Sonicwall
    Product
    Sma 7210 Firmware
    Vendor
    Sonicwall
    Product
    Sma 8200v
    Vendor
    Sonicwall
    Product
    Sma 8200v Firmware
    Vendor
    Sonicwall
    Product
    Sra Ex 7000
    Vendor
    Sonicwall
    Product
    Sra Ex 7000 Firmware
    Vendor
    Suse
    Product
    Linux Enterprise Micro

    Exploits

    https://santandersecurityresearch.github.io/blog/sshing_the_masses.htmlhttps://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txthttp://www.openwall.com/lists/oss-security/2024/07/03/11http://www.openwall.com/lists/oss-security/2024/07/04/2http://www.openwall.com/lists/oss-security/2024/07/08/2http://www.openwall.com/lists/oss-security/2024/07/09/5http://www.openwall.com/lists/oss-security/2024/07/10/1https://santandersecurityresearch.github.io/blog/sshing_the_masses.htmlhttps://www.exploit-db.com/exploits/52269https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txthttps://www.vicarius.io/vsociety/posts/regresshion-an-openssh-regression-error-cve-2024-6387https://www.exploit-db.com/exploits/52269https://github.com/0x4D31/cve-2024-6387_hasshhttps://github.com/4lxprime/regreSSHivehttps://github.com/7etsuo/cve-2024-6387-pochttps://github.com/ACHUX21/checker-CVE-2024-6387https://github.com/acrono/cve-2024-6387-pochttps://github.com/ahlfors/CVE-2024-6387https://github.com/AiGptCode/ssh_exploiter_CVE-2024-6387https://github.com/al7araziruby-jpg/CVE-2024-6387-OpenSSH-Analysishttps://github.com/alex14324/ssh_poc2024https://github.com/almogopp/OpenSSH-CVE-2024-6387-Fixhttps://github.com/anhvutuan/CVE-2024-6387-poc-1https://github.com/Ap0dexMe0/CVE-2024-6387https://github.com/arielrbrdev/redteamlab1https://github.com/awusan125/test_for6387https://github.com/AzrDll/CVE-2024-6387https://github.com/azurejoga/CVE-2024-6387-how-to-fixhttps://github.com/betancour/OpenSSH-Vulnerability-testhttps://github.com/bigb0x/CVE-2024-6387https://github.com/BrandonLynch2402/cve-2024-6387-nuclei-templatehttps://github.com/CiderAndWhisky/regression-scannerhttps://github.com/CognisysGroup/CVE-2024-6387-Checkerhttps://github.com/d0rb/CVE-2024-6387https://github.com/daniel-odrinski/CVE-2024-6387-Mitigation-Ansible-Playbookhttps://github.com/dawnl3ss/CVE-2024-6387https://github.com/devarshishimpi/CVE-2024-6387-Checkhttps://github.com/dgourillon/mitigate-CVE-2024-6387https://github.com/DimaMend/cve-2024-6387-pochttps://github.com/Doux-x/CVE-2024-6387-analysishttps://github.com/dream434/CVE-2024-6387https://github.com/edsonjt81/CVE-2024-6387_Checkhttps://github.com/FerasAlrimali/CVE-2024-6387-POChttps://github.com/filipi86/CVE-2024-6387-Vulnerability-Checkerhttps://github.com/getdrive/CVE-2024-6387-PoChttps://github.com/grupooruss/CVE-2024-6387https://github.com/HadesNull123/CVE-2024-6387_Checkhttps://github.com/harshinsecurity/sentinelsshhttps://github.com/hasan8babiker/CVE-2024-6387https://github.com/hssmo/cve-2024-6387_AImadehttps://github.com/identity-threat-labs/Article-RegreSSHion-CVE-2024-6387https://github.com/identity-threat-labs/CVE-2024-6387-Vulnerability-Checkerhttps://github.com/imv7/CVE-2024-6387https://github.com/invaderslabs/regreSSHion-CVE-2024-6387-https://github.com/jack0we/CVE-2024-6387https://github.com/JackSparrowhk/ssh-CVE-2024-6387-pochttps://github.com/jocker2410/CVE-2024-6387_pochttps://github.com/kaleth4/CVE-2024-6387https://github.com/Karmakstylez/CVE-2024-6387https://github.com/kinu404/CVE-2024-6387https://github.com/kubota/CVE-2024-6387-Vulnerability-Checkerhttps://github.com/l0n3m4n/CVE-2024-6387https://github.com/lala-amber/CVE-2024-6387https://github.com/lflare/cve-2024-6387-pochttps://github.com/l-urk/CVE-2024-6387https://github.com/m0n3ef/regreSSHion-Checkerhttps://github.com/moften/regreSSHion-CVE-2024-6387https://github.com/mrmtwoj/CVE-2024-6387https://github.com/MrR0b0t19/CVE-2024-6387-Exploit-POChttps://github.com/Mufti22/CVE-2024-6387-checkherhttps://github.com/muyuanlove/CVE-2024-6387fixshellhttps://github.com/n1cks0n/Test_CVE-2024-6387https://github.com/Ngagne-Demba-Dia/CVE-2024-6387-corrigeehttps://github.com/no-one-sec/CVE-2024-6387https://github.com/OhDamnn/Noregresshhttps://github.com/OHHDamnBRO/Noregresshhttps://github.com/oseasfr/Scanner_CVE_OpenSSHhttps://github.com/P4x1s/CVE-2024-6387https://github.com/paradessia/CVE-2024-6387-nmaphttps://github.com/particle99/CVE-2024-6387-POChttps://github.com/passwa11/cve-2024-6387-pochttps://github.com/prelearn-code/CVE-2024-6387https://github.com/PrincipalAnthony/CVE-2024-6387-Updated-x64bithttps://github.com/R4Tw1z/CVE-2024-6387https://github.com/redux-sibi-jose/mitigate_sshhttps://github.com/Remnant-DB/CVE-2024-6387https://github.com/RickGeex/CVE-2024-6387-Checkerhttps://github.com/rumochnaya/openssh-cve-2024-6387.shhttps://github.com/s1d6point7bugcrowd/CVE-2024-6387-Race-Condition-in-Signal-Handling-for-OpenSSHhttps://github.com/sardine-web/CVE-2024-6387_Checkhttps://github.com/sardine-web/CVE-2024-6387-templatehttps://github.com/shamo0/CVE-2024-6387_PoChttps://github.com/shyrwall/cve-2024-6387-pochttps://github.com/SkyGodling/CVE-2024-6387-POChttps://github.com/sms2056/CVE-2024-6387https://github.com/sxlmnwb/CVE-2024-6387https://github.com/Symbolexe/CVE-2024-6387https://github.com/t3rry327/cve-2024-6387-pochttps://github.com/TAM-K592/CVE-2024-6387https://github.com/teamos-hub/regreSSHionhttps://github.com/th3gokul/CVE-2024-6387https://github.com/ThatNotEasy/CVE-2024-6387https://github.com/thegenetic/CVE-2024-6387-exploithttps://github.com/turbobit/CVE-2024-6387-OpenSSH-Vulnerability-Checkerhttps://github.com/vkaushik-chef/regreSSHionhttps://github.com/vuducmanhno100-cloud/CVE-2024-6387https://github.com/wiggels/regresshion-checkhttps://github.com/xaitax/CVE-2024-6387_Checkhttps://github.com/xiw1ll/CVE-2024-6387_Checkerhttps://github.com/xonoxitron/regreSSHionhttps://github.com/xonoxitron/regreSSHion-checkerhttps://github.com/X-Projetion/CVE-2023-4596-OpenSSH-Multi-Checkerhttps://github.com/xristos8574/regreSSHion-nmap-scannerhttps://github.com/YassDEV221608/CVE-2024-6387https://github.com/YassDEV221608/CVE-2024-6387_PoChttps://github.com/zenzue/CVE-2024-6387-Mitigationhttps://github.com/zgzhang/cve-2024-6387-poc

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High