OpenSSH Security Update – 01 July 2024

OpenSSH released a security update to fix a vulnerability affecting all versions of OpenSSH between 8.5p1 and 9.7p1.

The addressed vulnerability could allow the unauthenticated remote attacker to execute arbitrary code with root privileges and gain access to the affected system by sending specially crafted requests.

OpenSSH Code Execution Vulnerability (CVE-2024-6387):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities

CVE-2024-6387

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed and should check with its vendors for updates if any.

OpenSSH Security Advisory

References