CVE-2024-6409

Scores

EPSS

0.782medium78.2%
0%20%40%60%80%100%

Percentile: 78.2%

CVSS

7.0high3.x
0246810

CVSS Score: 7.0/10

All CVSS Scores

CVSS 3.x
7.0

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

Description

A race condition vulnerability was discovered in how signals are handled by OpenSSH’s server (sshd). If a remote attacker does not authenticate within a set time period, then sshd’s SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog(). As a consequence of a successful attack, in the worst case scenario, an attacker may be able to perform a remote code execution (RCE) as an unprivileged user running the sshd server.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debianredhatubuntu

CWEs

CWE-364

Related Vulnerabilities

Vulnerable Software (9)

Type: Configuration

Product: openssh

Operating System: ubuntu focal 20.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: openssh

Operating System: ubuntu jammy 22.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: openssh

Operating System: rhel

Trait:
{  "fixed": "8.7p1-38.el9_4.4"}

Source: redhat

Type: Configuration

Product: openssh

Operating System: rhel 9

Trait:
{  "fixed": "8.7p1-38.el9_4.4"}

Source: redhat

Type: Configuration

Product: openssh

Operating System: rhel

Trait:
{  "fixed": "8.7p1-12.el9_0.3"}

Source: redhat

Type: Configuration

Product: openssh

Operating System: rhel

Trait:
{  "fixed": "8.7p1-30.el9_2.7"}

Source: redhat

Type: Configuration

Product: openssh

Operating System: debian

Trait:
{  "unaffected": true}

Source: debian

Type: Configuration

Product: openssh-ssh1

Operating System: ubuntu focal 20.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: openssh-ssh1

Operating System: ubuntu jammy 22.04

Trait:
{  "unaffected": true}

Source: ubuntu