References https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6387 https://nvd.nist.gov/vuln/detail/cve-2024-6387 https://access.redhat.com/security/cve/cve-2024-6387 https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server https://ubuntu.com/security/cve-2024-6387 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssh-rce-2024 https://www.rapid7.com/db/vulnerabilities/openbsd-openssh-cve-2024-6387/
Related VulnerabilitiesOpenSSH ProxyCommand 命令注入漏洞PoCCVE-2025-32433: Erlang/OTP SSH - Remote Code ExecutionPoCCVE-2018-16059: WirelessHART Fieldgate SWG70 3.0 - Local File InclusionPoCCVE-2023-48795: OpenSSH Terrapin Attack - DetectionPoCCVE-2001-1473: Deprecated SSHv1 Protocol DetectionPoCunrestricted-ssh-access: Unrestricted - SSH AccessPoCiam-ssh-keys-rotation: SSH Key Rotation - 90-Day PolicyPoCgcloud-vm-project-ssh-keys-enabled: Block Project-Wide SSH Keys Not EnabledPoCssh-gssapiauthentication-disabled: sshd GSSAPIAuthentication - DisabledPoCssh-hostbasedauth-disabled: Ensure SSH HostbasedAuthentication - DisabledPoCprivesc-ssh-agent: ssh-agent - Privilege EscalationPoCprivesc-sshpass: sshpass - Privilege Escalation