← voltar
CVE-2024-6387

Openssh: regresshion - race condition in ssh allows rce/dos

CVSS 8.1 HIGHEPSS 99.5%CWE-364
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
PoCs públicas encontradas97
githubgithub.com/xaitax/CVE-2024-6387_Check523githubgithub.com/zgzhang/cve-2024-6387-poc493githubgithub.com/acrono/cve-2024-6387-poc381githubgithub.com/Karmakstylez/CVE-2024-6387181githubgithub.com/lflare/cve-2024-6387-poc128githubgithub.com/l0n3m4n/CVE-2024-6387109githubgithub.com/filipi86/CVE-2024-6387-Vulnerability-Checker100githubgithub.com/xonoxitron/regreSSHion66githubgithub.com/d0rb/CVE-2024-638750githubgithub.com/bigb0x/CVE-2024-638735githubgithub.com/getdrive/CVE-2024-6387-PoC24githubgithub.com/sxlmnwb/CVE-2024-638721githubgithub.com/TAM-K592/CVE-2024-638714githubgithub.com/thegenetic/CVE-2024-6387-exploit14githubgithub.com/devarshishimpi/CVE-2024-6387-Check14githubgithub.com/l-urk/CVE-2024-638712githubgithub.com/AiGptCode/ssh_exploiter_CVE-2024-638711githubgithub.com/0x4D31/cve-2024-6387_hassh10githubgithub.com/xonoxitron/regreSSHion-checker10githubgithub.com/P4x1s/CVE-2024-63878githubgithub.com/wiggels/regresshion-check6githubgithub.com/azurejoga/CVE-2024-6387-how-to-fix5githubgithub.com/MrR0b0t19/CVE-2024-6387-Exploit-POC4githubgithub.com/kinu404/CVE-2024-63874githubgithub.com/paradessia/CVE-2024-6387-nmap4githubgithub.com/harshinsecurity/sentinelssh4githubgithub.com/th3gokul/CVE-2024-63874githubgithub.com/lala-amber/CVE-2024-63874githubgithub.com/BrandonLynch2402/cve-2024-6387-nuclei-template3githubgithub.com/awusan125/test_for63873githubgithub.com/PrincipalAnthony/CVE-2024-6387-Updated-x64bit3githubgithub.com/betancour/OpenSSH-Vulnerability-test2githubgithub.com/ahlfors/CVE-2024-63872githubgithub.com/anhvutuan/CVE-2024-6387-poc-12githubgithub.com/OHHDamnBRO/Noregressh2githubgithub.com/identity-threat-labs/CVE-2024-6387-Vulnerability-Checker2githubgithub.com/Symbolexe/CVE-2024-63872githubgithub.com/prelearn-code/CVE-2024-63872githubgithub.com/Ap0dexMe0/CVE-2024-63872githubgithub.com/ACHUX21/checker-CVE-2024-63872githubgithub.com/grupooruss/CVE-2024-63872githubgithub.com/sardine-web/CVE-2024-6387-template2githubgithub.com/muyuanlove/CVE-2024-6387fixshell2githubgithub.com/redux-sibi-jose/mitigate_ssh1githubgithub.com/7etsuo/cve-2024-6387-poc1githubgithub.com/passwa11/cve-2024-6387-poc1githubgithub.com/teamos-hub/regreSSHion1githubgithub.com/R4Tw1z/CVE-2024-63871githubgithub.com/shamo0/CVE-2024-6387_PoC1githubgithub.com/rumochnaya/openssh-cve-2024-6387.sh1githubgithub.com/xristos8574/regreSSHion-nmap-scanner1githubgithub.com/n1cks0n/Test_CVE-2024-63871githubgithub.com/RickGeex/CVE-2024-6387-Checker1githubgithub.com/turbobit/CVE-2024-6387-OpenSSH-Vulnerability-Checker1githubgithub.com/sardine-web/CVE-2024-6387_Check1githubgithub.com/alex14324/ssh_poc20241githubgithub.com/X-Projetion/CVE-2023-4596-OpenSSH-Multi-Checker1githubgithub.com/identity-threat-labs/Article-RegreSSHion-CVE-2024-63871githubgithub.com/xiw1ll/CVE-2024-6387_Checker1githubgithub.com/t3rry327/cve-2024-6387-poc0githubgithub.com/Remnant-DB/CVE-2024-63870githubgithub.com/CognisysGroup/CVE-2024-6387-Checker0githubgithub.com/edsonjt81/CVE-2024-6387_Check0githubgithub.com/imv7/CVE-2024-63870githubgithub.com/dawnl3ss/CVE-2024-63870githubgithub.com/no-one-sec/CVE-2024-63870githubgithub.com/vkaushik-chef/regreSSHion0githubgithub.com/dgourillon/mitigate-CVE-2024-63870githubgithub.com/mrmtwoj/CVE-2024-63870githubgithub.com/particle99/CVE-2024-6387-POC0githubgithub.com/kubota/CVE-2024-6387-Vulnerability-Checker0githubgithub.com/DimaMend/cve-2024-6387-poc0githubgithub.com/invaderslabs/regreSSHion-CVE-2024-6387-0githubgithub.com/4lxprime/regreSSHive0githubgithub.com/dream434/CVE-2024-63870githubgithub.com/hssmo/cve-2024-6387_AImade0githubgithub.com/zenzue/CVE-2024-6387-Mitigation0githubgithub.com/daniel-odrinski/CVE-2024-6387-Mitigation-Ansible-Playbook0githubgithub.com/Doux-x/CVE-2024-6387-analysis0githubgithub.com/kaleth4/CVE-2024-63870githubgithub.com/s1d6point7bugcrowd/CVE-2024-6387-Race-Condition-in-Signal-Handling-for-OpenSSH0githubgithub.com/almogopp/OpenSSH-CVE-2024-6387-Fix0githubgithub.com/HadesNull123/CVE-2024-6387_Check0githubgithub.com/CiderAndWhisky/regression-scanner0githubgithub.com/oseasfr/Scanner_CVE_OpenSSH0githubgithub.com/Mufti22/CVE-2024-6387-checkher0githubgithub.com/YassDEV221608/CVE-2024-63870githubgithub.com/jack0we/CVE-2024-63870githubgithub.com/FerasAlrimali/CVE-2024-6387-POC0githubgithub.com/vuducmanhno100-cloud/CVE-2024-63870githubgithub.com/moften/regreSSHion-CVE-2024-63870githubgithub.com/jocker2410/CVE-2024-6387_poc0githubgithub.com/JackSparrowhk/ssh-CVE-2024-6387-poc0githubgithub.com/Ngagne-Demba-Dia/CVE-2024-6387-corrigee0githubgithub.com/sms2056/CVE-2024-63870cve_referencewww.exploit-db.com/exploits/52269não verificadocve_referencepacketstorm.news/files/id/190587/não verificado
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →