A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
https://www.helpnetsecurity.com/2026/02/19/managed-xdr-threat-report-security-programs/
https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-05
https://www.cisa.gov/news-events/ics-advisories/icsa-25-100-09
https://thehackernews.com/2025/02/new-openssh-flaws-enable-man-in-middle.html
https://www.securityweek.com/juniper-networks-fixes-high-severity-vulnerabilities-in-junos-os/
https://securelist.com/exploits-and-vulnerabilities-q3-2024/114839/
https://www.cisa.gov/news-events/ics-advisories/icsa-24-256-15
https://www.securityweek.com/cisco-patches-high-severity-vulnerability-reported-by-nsa/
https://support.apple.com/en-us/HT214118
https://www.openwall.com/lists/oss-security/2024/07/10/2
https://securityaffairs.com/165535/hacking/openssh-flaw-cve-2024-6409.html?web_view=true
https://github.com/andykrohg/acs-cve-plugin
https://github.com/saaheerpurav/cve-twin
https://github.com/Induj1/cve-twin
https://github.com/Sujan833/NLP-Driven-Cyber-Threat-Intelligence-Agent
https://github.com/hasan8babiker/CVE-2024-6387
https://github.com/cytem-io/backcheck-core
https://github.com/kun9497/assay
https://github.com/al7araziruby-jpg/CVE-2024-6387-OpenSSH-Analysis
https://github.com/mainfiji/layer8-security-incident-response
https://github.com/m0n3ef/regreSSHion-Checker
https://github.com/sawantdakshta577/vulnerability-CVE-Scanner
https://github.com/dabumana/nvd-go
https://github.com/Babatomiwa001/DVWA-Vulnerability-Scan-and-Exploit-Simulation
https://github.com/GurukiranShiv/threat-intel-graph-platform
https://github.com/GurukiranShiv/Threat-Intel-Graph-Platform
https://github.com/janderik/vuln-forge
https://github.com/avnt06/Threat_Inspector
https://github.com/fDarkShadow/noctis
https://github.com/safetylab/ShadowSecurityScanner
https://github.com/harshweb-cyber/Netscout
https://github.com/IgorBVieira/automated-cve-scanner
https://github.com/GiovanniBBenedetti/scan-cve-surface
https://github.com/PERARASU10/cve-analyzer-pro
https://github.com/RENE155/cve-analize
https://github.com/offseq/threat-finder
https://github.com/huatusss/cve-scanner-2
https://github.com/p1ngzac/cve-lookup
https://github.com/ZacSilver-Fedora/cve-lookup
https://github.com/BolajiEdu/cve-network-scanner
https://github.com/oseasfr/Scanner_CVE_SSH
https://github.com/oseasfr/Scanner_CVE_OpenSSH
https://github.com/zencefilefendi/dedekorkut
https://github.com/Manishadua/devsecops-daily
https://github.com/Boney-cyriac-ITsecurity/network-scanner
https://github.com/nextgensoumen/soc-pulse
https://github.com/EliV16/sshd-security-checker
https://github.com/0xrpheus/wraith
https://github.com/kaleth4/CVE-2024-6387
https://github.com/xiexie-qiuligao/cve-
https://github.com/Doux-x/CVE-2024-6387-analysis
https://github.com/AbdulMoiz6692/cve-vulnerability-scanner-pro
https://github.com/hermestoola/bb-hunter-pro
https://github.com/RehmanAjaz/CVE-Scanner
https://github.com/Remnant-DB/CVE-2024-6387
https://github.com/OMALICHAC/VulnScout-Network-Vulnerability-Scanner
https://github.com/Sandro-GG/pentesting-bachelor-thesis
https://github.com/botzero-net/enterprise-security-toolkit
https://github.com/asif-kabir-emon/ip-vulnerability-monitor-cve-analysis
https://github.com/arielrbrdev/redteamlab1
https://github.com/vBarbaros/security-faux-pas
https://github.com/OhDamnn/Noregressh
https://github.com/moften/regreSSHion-CVE-2024-6387
https://github.com/Sucuri-Labs/CVE-2025-57819-ioc-check
https://github.com/xiw1ll/CVE-2024-6387_Checker
https://github.com/vitalii-moholivskyi/selected-cve-dataset-2024
https://github.com/krlabs/openssh-vulnerabilities
https://github.com/oxapavan/CVE-2024-6387
https://github.com/MuhammadMuazen/thagarat
https://cert-portal.siemens.com/productcert/html/ssa-446545.html
https://github.com/identity-threat-labs/Article-RegreSSHion-CVE-2024-6387
https://github.com/identity-threat-labs/CVE-2024-6387-Vulnerability-Checker
https://github.com/HadesNull123/CVE-2024-6387_Check
https://github.com/ryanalieh/openSSH-scanner
https://github.com/bigb0x/OpenSSH-Scanner
https://github.com/almogopp/OpenSSH-CVE-2024-6387-Fix
https://github.com/s1d6point7bugcrowd/CVE-2024-6387-Race-Condition-in-Signal-Handling-for-OpenSSH
https://github.com/niktoproject/CVE-202406387_Check.py
https://github.com/X-Projetion/CVE-2023-4596-OpenSSH-Multi-Checker
https://github.com/alex14324/ssh_poc2024
https://github.com/langeaustin/RegresshionCVE
https://github.com/Jhonsonwannaa/CVE-2024-6387
https://github.com/k4t3pr0/CVE-2024-6387-Check
https://github.com/Passyed/regreSSHion-Fix
https://github.com/Sibijo/mitigate_ssh
https://github.com/ThemeHackers/CVE-2024-6387
https://github.com/bigb0x/SSH-Scanner
https://github.com/MrR0b0t19/CVE-6387-SSH-v2
https://github.com/DimaMend/cve-2024-6387-poc
https://github.com/kubota/CVE-2024-6387-Vulnerability-Checker
https://github.com/filipi86/CVE-2024-6387-Vulnerability-Checker
https://github.com/mrmtwoj/CVE-2024-6387
https://github.com/vkaushik-chef/regreSSHion
https://github.com/azurejoga/CVE-2024-6387-how-to-fix
https://github.com/dgicloud/patch_regreSSHion
https://github.com/SiberianHacker/CVE-2024-6387-Finder
https://github.com/imv7/CVE-2024-6387
https://github.com/sardine-web/CVE-2024-6387-template
https://github.com/0x4D31/cve-2024-6387_hassh
https://github.com/sardine-web/CVE-2024-6387_Check
https://github.com/lala-amber/CVE-2024-6387
https://github.com/invaderslabs/regreSSHion-CVE-2024-6387-
https://github.com/sms2056/CVE-2024-6387
https://github.com/turbobit/CVE-2024-6387-OpenSSH-Vulnerability-Checker
Published: 2024-07-01
Updated: 2026-09-01
Named Vulnerability: regreSSHionNamed Vulnerability: RegreSSHion
Base Score: 7.6
Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C
Severity: High
Base Score: 8.1
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: High
Base Score: 9.2
Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity: Critical
EPSS: 0.99506
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability Being Monitored