OpenSSH(OpenBSD Secure Shell)是加拿大OpenBSD计划组的一套用于安全访问远程计算机的连接工具。该工具是SSH协议的开源实现,支持对所有的传输进行加密,可有效阻止窃听、连接劫持以及其他网络级的攻击。 OpenSSH 存在安全漏洞,该漏洞源于信号处理程序中存在竞争条件,攻击者利用该漏洞可以在无需认证的情况下远程执行任意代码并获得系统控制权。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | - | 8.5p1 ~ 9.7p1 | - |
|
| Red Hat | Red Hat Enterprise Linux 9 | 0:8.7p1-38.el9_4.1 ~ * |
cpe:/a:redhat:enterprise_linux:9::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9 | 0:8.7p1-38.el9_4.1 ~ * |
cpe:/a:redhat:enterprise_linux:9::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | 0:8.7p1-12.el9_0.1 ~ * |
cpe:/a:redhat:rhel_e4s:9.0::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | 0:8.7p1-30.el9_2.4 ~ * |
cpe:/a:redhat:rhel_eus:9.2::appstream
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.13 | 413.92.202407091321-0 ~ * |
cpe:/a:redhat:openshift:4.13::el8
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.14 | 414.92.202407091253-0 ~ * |
cpe:/a:redhat:openshift:4.14::el8
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.15 | 415.92.202407091355-0 ~ * |
cpe:/a:redhat:openshift:4.15::el8
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 416.94.202407081958-0 ~ * |
cpe:/a:redhat:openshift:4.16::el9
|
|
| Red Hat | Red Hat Ceph Storage 5 | - |
cpe:/a:redhat:ceph_storage:5
|
|
| Red Hat | Red Hat Ceph Storage 6 | - |
cpe:/a:redhat:ceph_storage:6
|
|
| Red Hat | Red Hat Ceph Storage 7 | - |
cpe:/a:redhat:ceph_storage:7
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | a signal handler race condition in OpenSSH's server (sshd) | https://github.com/zgzhang/cve-2024-6387-poc | POC Details |
| 2 | None | https://github.com/acrono/cve-2024-6387-poc | POC Details |
| 3 | None | https://github.com/lflare/cve-2024-6387-poc | POC Details |
| 4 | Spirit - Network Pentest Tools CVE-2024-6387 | https://github.com/theaog/spirit | POC Details |
| 5 | None | https://github.com/shyrwall/cve-2024-6387-poc | POC Details |
| 6 | None | https://github.com/getdrive/CVE-2024-6387-PoC | POC Details |
| 7 | SSHd cve-2024-6387-poc | https://github.com/FerasAlrimali/CVE-2024-6387-POC | POC Details |
| 8 | None | https://github.com/passwa11/cve-2024-6387-poc | POC Details |
| 9 | None | https://github.com/jack0we/CVE-2024-6387 | POC Details |
| 10 | CVE-2024-6387_Check is a lightweight, efficient tool designed to identify servers running vulnerable versions of OpenSSH | https://github.com/xaitax/CVE-2024-6387_Check | POC Details |
| 11 | Bulk Scanning Tool for OpenSSH CVE-2024-6387, CVE-2006-5051 , CVE-2008-4109 and others. | https://github.com/bigb0x/CVE-2024-6387 | POC Details |
| 12 | CLI Tool to Check SSH Servers for Vulnerability to CVE-2024-6387 | https://github.com/wiggels/regresshion-check | POC Details |
| 13 | SSH RCE PoC CVE-2024-6387 | https://github.com/3yujw7njai/CVE-2024-6387 | POC Details |
| 14 | OpenSSH CVE-2024-6387 Vulnerability Checker | https://github.com/betancour/OpenSSH-Vulnerability-test | POC Details |
| 15 | None | https://github.com/zgimszhd61/cve-2024-6387-poc | POC Details |
| 16 | None | https://github.com/yya1233/CVE-2024-6387-Updated-SSH-RCE | POC Details |
| 17 | None | https://github.com/muyuanlove/CVE-2024-6387fixshell | POC Details |
| 18 | Recently, the OpenSSH maintainers released security updates to fix a critical vulnerability that could lead to unauthenticated remote code execution (RCE) with root privileges. This vulnerability, identified as CVE-2024-6387, resides in the OpenSSH server component (sshd), which is designed to listen for connections from client applications. | https://github.com/TAM-K592/CVE-2024-6387 | POC Details |
| 19 | This is a POC I wrote for CVE-2024-6387 | https://github.com/teamos-hub/regreSSHion | POC Details |
| 20 | None | https://github.com/Maikefee/CVE-2024-6387_Check.py | POC Details |
| 21 | None | https://github.com/ahlfors/CVE-2024-6387 | POC Details |
| 22 | None | https://github.com/Mufti22/CVE-2024-6387-checkher | POC Details |
| 23 | CVE-2024-6387 exploit | https://github.com/thegenetic/CVE-2024-6387-exploit | POC Details |
| 24 | RCE OpenSSH CVE-2024-6387 Check | https://github.com/HadesNull123/CVE-2024-6387_Check | POC Details |
| 25 | This script, created by R4Tw1z, is designed to scan IP addresses to check if they are running a potentially vulnerable version of OpenSSH. The tool leverages multi-threading to optimize scanning performance and handle multiple IP addresses concurrently. | https://github.com/R4Tw1z/CVE-2024-6387 | POC Details |
| 26 | This Python script exploits a remote code execution vulnerability (CVE-2024-6387) in OpenSSH. | https://github.com/d0rb/CVE-2024-6387 | POC Details |
| 27 | None | https://github.com/oliferFord/CVE-2024-6387-SSH-RCE | POC Details |
| 28 | Used to detect ssh servers vulnerable to CVE-2024-6387. Shameless robbery from https://github.com/bigb0x/CVE-2024-6387 using ChatGPT to translate the code to PHP. | https://github.com/CiderAndWhisky/regression-scanner | POC Details |
| 29 | Script for checking CVE-2024-6387 (regreSSHion) | https://github.com/shamo0/CVE-2024-6387_PoC | POC Details |
| 30 | CVE-2024-6387-nmap | https://github.com/paradessia/CVE-2024-6387-nmap | POC Details |
No comments yet