Target Industry

Indiscriminate, opportunistic targeting.

Overview

A new OpenSSH unauthenticated remote code execution (RCE) flaw, named ‘regreSSHion’ has been discovered that provides root privileges on glibc-based Linux systems. OpenSSH is a suite of networking utilities based on the Secure Shell (SSH) protocol, which is used for a range of remote services as well as file transfers via Secure Copy Protocol (SCP) and Secure File Transfer Protocol (SFTP).

The flaw, tracked as CVE-2024-6387 (CVSSv3.1 score: 8.1), was discovered by Qualys back in May and is caused by a signal handler race condition in sshd that allows unauthenticated remote threat actors to execute arbitrary code as root.

Impact

Successful exploitation of CVE-2024-6387 could lead to full system compromise where a threat actor could execute arbitrary code with the highest-level privileges. This would likely result in a complete hijacking of the target system with potential follow up operations including malware deployment, data manipulation, and the creation of backdoors for persistent access.

Affected Products

The regreSSHion flaw impacts OpenSSH servers on Linux from version 8.5p1 up to, but not including, 9.8p1. Versions 4.4p1 up to, but not including, 8.5p1 are not vulnerable, resulting from a patch for CVE-2006-5051.

Versions older than 4.4p1 are vulnerable to regreSSHion unless they are patched for CVE-2006-5051 and CVE-2008-4109.

Qualys also highlighted that OpenBSD systems are not impacted by CVE-2006-5051 thanks to a secure mechanism introduced back in 2001. The researchers also noted that while the flaw likely also impacts macOS and Windows, its exploitability on these systems has yet to be verified.

Containment, Mitigations & Remediations

Qualys strongly recommends that the following mitigation steps are applied:

  • Apply the latest available update for the OpenSSH server (version 9.8p1)
  • Restrict SSH access using network-based controls such as firewalls
  • Implement network segmentation to prevent lateral movement
  • If the OpenSSH server cannot be immediately updated, users should set the ‘LoginGraceTime’ to 0 in the sshd configuration file but note that this can expose the server to denial-of-service (DoS) attacks.

Indicators of Compromise

No specific Indicators of Compromise (IoCs) are available currently.

Threat Landscape

OpenSSH occupies a significant proportion of the secure shell market share. Given that threat actors generally utilise a combination of probability and asset value to determine which attack surfaces to focus on, OpenSSH vulnerabilities will likely become a prime target. Due to the fact that OpenSSH is a commonly relied upon networking utility which is used for a range of remote services as well as file transfers via SCP and SFTP, threat actors will continue to exploit OpenSSH vulnerabilities in order to complete pre-defined objectives.

Threat Group

No attribution to specific threat actors or groups has been identified at the time of writing.

Mitre Methodologies

Common Weakness Enumeration (CWE)

CWE-364 – Signal Handler Race Condition

Further Information

Qualys blog.

Intelligence Terminology Yardstick

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content