Lucene search

K
broadcomBroadcom Security ResponseBSNSA24691
HistoryJul 15, 2024 - 12:00 a.m.

CVE-2024-6387: Remote Unauthorized Code Execution Vulnerability in openSSH server (regreSSHion)

2024-07-1500:00:00
Broadcom Security Response
support.broadcom.com
26
cve-2024-6387
remote code execution
unauthenticated attacker
race condition
arbitrary code
glibc-based linux
vendor note

AI Score

8.4

Confidence

Low

EPSS

0.715

Percentile

98.1%

OpenSSH contains a remote code execution (RCE) vulnerability, exploitable by an unauthenticated attacker through a race condition. Successful exploitation can allow for the remote execution of arbitrary code.
Note: This flaw has been demonstrated to be exploitable remotely on glibc-based Linux systems. Other libc or operating systems were not examined, however, the vendor has indicated in the 9.8 release notes that “exploitation on non-glibc systems is conceivable”.