Zultys Security Advisory Notice - SAN24-005 Rev 1.0

‘RegreSSHion’ vulnerability in OpenSSH (CVE-2024-6387)

Severity: No Impact

Published: 2024-07-02

Updated: 2024-07-02

Revision: 1.0

Evaluated Products

MX-SE, MX-SE II, MX-E and MX-Virtual systems

Impacted Products

None

Affected Releases

Not applicable

Impacted 3rd Party Products

Not applicable

Introduction

On July 1, 2024 details of a vulnerability impacting OpenSSH was published in the National

Vulnerability Database under CVE-2024-6387. The vulnerability relates to a signal handler race condition which may be exploited. The vulnerability is commonly referred to as the ‘RegreSSHion’ bug.

Description

The MX-SE, MX-SE II, MX-E and MX-Virtual products are not impacted.

Contact

If additional information is required contact support@zultys.com or your Authorized Zultys Channel Partner.