logo

RCE vulnerability in OpenSSH – RegreSSHion (CVE-2024-6387)

ID: 2b84c19c-02e5-5c4a-9bb4-e265c7dccd14

STIX ID: report--2b84c19c-02e5-5c4a-9bb4-e265c7dccd14

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2024-07-02

Date Updated: 2026-03-24

Author: Eime Adomaviciute

...
...

This report details CVE-2024-6387 (“regreSSHion”), a high-severity remote code execution vulnerability in OpenSSH on glibc-based Linux (affected versions <4.4p1 and 8.5p1–9.7p; OpenBSD unaffected), caused by a regression of an older bug; it advises immediate upgrades to OpenSSH 9.8 or patched distro packages, minimizing SSH exposure to trusted networks, strengthening authentication and monitoring, and, if patching is not possible, setting LoginGraceTime=0 to remove RCE risk at the cost of potential DoS, noting active PoCs and the potential for real-world exploitation despite complexity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.