FreeBSD Security Update – 13 August 2024

FreeBSD systems have released a security update to address a vulnerability across FreeBSD openssh.

The addressed vulnerability could allow the remote unauthenticated attacker to execute arbitrary code with root privileges, and gain access to the affected system by sending a specially crafted request.

The addressed vulnerability:

FreeBSD Code Execution Vulnerability (CVE-2024-7589):

  • CVSS: 8.1
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities

CVE-2024-7589

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed and should check with its vendors for updates if any.

FreeBSD Security Update

References