CVE-2024-6387

critical

Description

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

References

https://github.com/andykrohg/acs-cve-plugin

https://github.com/saaheerpurav/cve-twin

https://github.com/Induj1/cve-twin

https://github.com/Sujan833/NLP-Driven-Cyber-Threat-Intelligence-Agent

https://github.com/hasan8babiker/CVE-2024-6387

https://github.com/cytem-io/backcheck-core

https://github.com/kun9497/assay

https://github.com/al7araziruby-jpg/CVE-2024-6387-OpenSSH-Analysis

https://github.com/mainfiji/layer8-security-incident-response

https://github.com/m0n3ef/regreSSHion-Checker

https://github.com/sawantdakshta577/vulnerability-CVE-Scanner

https://github.com/dabumana/nvd-go

https://github.com/Babatomiwa001/DVWA-Vulnerability-Scan-and-Exploit-Simulation

https://github.com/GurukiranShiv/threat-intel-graph-platform

https://github.com/GurukiranShiv/Threat-Intel-Graph-Platform

https://github.com/janderik/vuln-forge

https://github.com/avnt06/Threat_Inspector

https://github.com/fDarkShadow/noctis

https://github.com/safetylab/ShadowSecurityScanner

https://github.com/harshweb-cyber/Netscout

https://github.com/IgorBVieira/automated-cve-scanner

https://github.com/GiovanniBBenedetti/scan-cve-surface

https://github.com/PERARASU10/cve-analyzer-pro

https://github.com/RENE155/cve-analize

https://github.com/offseq/threat-finder

https://github.com/huatusss/cve-scanner-2

https://github.com/p1ngzac/cve-lookup

https://github.com/ZacSilver-Fedora/cve-lookup

https://github.com/BolajiEdu/cve-network-scanner

https://github.com/oseasfr/Scanner_CVE_SSH

https://github.com/oseasfr/Scanner_CVE_OpenSSH

https://github.com/zencefilefendi/dedekorkut

https://github.com/Manishadua/devsecops-daily

https://github.com/Boney-cyriac-ITsecurity/network-scanner

https://github.com/nextgensoumen/soc-pulse

https://github.com/EliV16/sshd-security-checker

https://github.com/0xrpheus/wraith

https://github.com/kaleth4/CVE-2024-6387

https://github.com/xiexie-qiuligao/cve-

https://github.com/Doux-x/CVE-2024-6387-analysis

https://github.com/AbdulMoiz6692/cve-vulnerability-scanner-pro

https://github.com/hermestoola/bb-hunter-pro

https://github.com/RehmanAjaz/CVE-Scanner

https://github.com/Remnant-DB/CVE-2024-6387

https://github.com/OMALICHAC/VulnScout-Network-Vulnerability-Scanner

https://github.com/Sandro-GG/pentesting-bachelor-thesis

https://github.com/botzero-net/enterprise-security-toolkit

https://github.com/asif-kabir-emon/ip-vulnerability-monitor-cve-analysis

https://github.com/arielrbrdev/redteamlab1

https://github.com/vBarbaros/security-faux-pas

https://github.com/OhDamnn/Noregressh

https://github.com/moften/regreSSHion-CVE-2024-6387

https://github.com/Sucuri-Labs/CVE-2025-57819-ioc-check

https://github.com/xiw1ll/CVE-2024-6387_Checker

https://github.com/vitalii-moholivskyi/selected-cve-dataset-2024

https://github.com/krlabs/openssh-vulnerabilities

https://github.com/oxapavan/CVE-2024-6387

https://github.com/MuhammadMuazen/thagarat

https://cert-portal.siemens.com/productcert/html/ssa-446545.html

https://github.com/identity-threat-labs/Article-RegreSSHion-CVE-2024-6387

https://github.com/identity-threat-labs/CVE-2024-6387-Vulnerability-Checker

https://github.com/HadesNull123/CVE-2024-6387_Check

https://github.com/ryanalieh/openSSH-scanner

https://github.com/bigb0x/OpenSSH-Scanner

https://github.com/almogopp/OpenSSH-CVE-2024-6387-Fix

https://github.com/s1d6point7bugcrowd/CVE-2024-6387-Race-Condition-in-Signal-Handling-for-OpenSSH

https://github.com/niktoproject/CVE-202406387_Check.py

https://github.com/X-Projetion/CVE-2023-4596-OpenSSH-Multi-Checker

https://github.com/alex14324/ssh_poc2024

https://github.com/langeaustin/RegresshionCVE

https://github.com/Jhonsonwannaa/CVE-2024-6387

https://github.com/k4t3pr0/CVE-2024-6387-Check

https://github.com/Passyed/regreSSHion-Fix

https://github.com/Sibijo/mitigate_ssh

https://github.com/ThemeHackers/CVE-2024-6387

https://github.com/bigb0x/SSH-Scanner

https://github.com/MrR0b0t19/CVE-6387-SSH-v2

https://github.com/DimaMend/cve-2024-6387-poc

https://github.com/kubota/CVE-2024-6387-Vulnerability-Checker

https://github.com/filipi86/CVE-2024-6387-Vulnerability-Checker

https://github.com/mrmtwoj/CVE-2024-6387

https://github.com/vkaushik-chef/regreSSHion

https://github.com/azurejoga/CVE-2024-6387-how-to-fix

https://github.com/dgicloud/patch_regreSSHion

https://github.com/SiberianHacker/CVE-2024-6387-Finder

https://github.com/imv7/CVE-2024-6387

https://github.com/sardine-web/CVE-2024-6387-template

https://github.com/0x4D31/cve-2024-6387_hassh

https://github.com/sardine-web/CVE-2024-6387_Check

https://github.com/lala-amber/CVE-2024-6387

https://github.com/invaderslabs/regreSSHion-CVE-2024-6387-

https://github.com/sms2056/CVE-2024-6387

https://github.com/turbobit/CVE-2024-6387-OpenSSH-Vulnerability-Checker

https://github.com/JackSparrowhk/ssh-CVE-2024-6387-poc

https://github.com/liqhtnd/sshd-logingracetime0

Details

Source: Mitre, NVD

Published: 2024-07-01

Updated: 2026-09-01

Named Vulnerability: regreSSHionNamed Vulnerability: RegreSSHion

Risk Information

CVSS v2

Base Score: 7.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.1

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: High

CVSS v4

Base Score: 9.2

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: Critical

EPSS

EPSS: 0.99506

Vulnerability Watch

Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.

Vulnerability Being Monitored