Fiche vulnérabilité
CVE-2024-6387 : faille élevée sonicwall sma 6200 firmware (CVSS 8.1)
Description
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
En bref
- Sévérité
- Élevée (CVSS 8.1)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 1 juil. 2024
- Dernière mise à jour
- 1 sept. 2026
Produits concernés
- sonicwall sma 6200 firmware
- sonicwall sma 7200 firmware
- arista eos
- canonical ubuntu linux
- almalinux almalinux
- sonicwall sma 6210 firmware
- sonicwall sma 7210 firmware
- sonicwall sma 8200v firmware
- sonicwall sra ex 7000 firmware
- netapp a1k firmware
- netapp a70 firmware
- netapp a90 firmware
- netapp a700s firmware
- netapp 8300 firmware
- netapp 8700 firmware
- netapp a400 firmware
- netapp c400 firmware
- netapp a250 firmware
- netapp 500f firmware
- netapp c250 firmware
Références
- Fiche CVE-2024-6387 sur le NVD (NIST)
- access.redhat.com/errata/RHSA-2024:4312
- access.redhat.com/errata/RHSA-2024:4340
- access.redhat.com/errata/RHSA-2024:4389
- access.redhat.com/errata/RHSA-2024:4469
- access.redhat.com/errata/RHSA-2024:4474
- access.redhat.com/errata/RHSA-2024:4479
- access.redhat.com/errata/RHSA-2024:4484
- access.redhat.com/security/cve/CVE-2024-6387
- bugzilla.redhat.com/show_bug.cgi
- santandersecurityresearch.github.io/blog/sshing_the_masses.html
- openssh.com/txt/release-9.8
- qualys.com/2024/07/01/cve-2024-6387/regresshion.txt
- seclists.org/fulldisclosure/2024/Jul/18
- seclists.org/fulldisclosure/2024/Jul/19
- seclists.org/fulldisclosure/2024/Jul/20