{"id":56596,"date":"2024-07-17T00:00:00","date_gmt":"2024-07-17T00:00:00","guid":{"rendered":"urn:uuid:3e510beb-3725-3f44-bc94-914ef254ca78"},"modified":"2024-07-17T00:00:00","modified_gmt":"2024-07-17T00:00:00","slug":"the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\/","title":{"rendered":"The Potential Impact of the OpenSSH Vulnerabilities CVE-2024\u20136387 and CVE-2024-6409"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/cve-2024-6387:Large?qlt=80\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/24\/cve-2024-6387.png\" class=\"ff-og-image-inserted\"><\/div>\n<p>The \u201cregreSSHion\u201d vulnerability arises from the unsafe handling of the <i>SIGALRM<\/i> signal during SSH authentication. When the <i>LoginGraceTime<\/i> expires, the <i>SIGALRM<\/i> signal is raised, and the corresponding handler performs certain actions, including calling non-async-signal-safe functions like <i>syslog().<\/i> This can create a race condition, where the timing of operations could lead to memory corruption or other unexpected behaviors.<\/p>\n<p><span class=\"blockquote\"><span class=\"body-subhead-title\"><\/span><i>SIGALRM&nbsp;is a signal in Unix-like operating systems that indicates an alarm or timer expiration. When a process sets and a function triggers, it schedules a SIGALRM signal to be sent to the process after a specified number of seconds. This signal is commonly used for timing operations, such as implementing timeouts for network requests or scheduling periodic tasks. Processes can define custom signal handlers to respond to SIGALRM, allowing them to perform actions such as terminating processes, resetting timers, or managing execution time limits. Overall, SIGALRM facilitates time-sensitive operations within Unix processes by providing a mechanism to handle scheduled alarms and timing events.<\/i><\/span><\/p>\n<p>Exploiting CVE-2024\u20136387 requires an attacker to initiate thousands of connection attempts to trigger the race condition accurately. The process involves repeatedly setting and resetting <i>LoginGraceTime<\/i>, causing the server to invoke the <i>SIGALRM<\/i> signal handler. This requires precise timing and proper inputs to manipulate the server\u2019s memory layout, leading to heap corruption and code execution.<\/p>\n<p><span class=\"blockquote\"><span class=\"body-subhead-title\"><\/span><i>Signal handlers are special functions that get called in response to specific signals sent to a program. These signals can be generated, either by the operating system or by the program itself. However, not all functions are safe to call from within a signal handler since they may not be reentrant, therefore cannot safely be interrupted and called again (\u201casync-signal-safe\u201d). For instance, syslog() is a function used to log messages to the system logger and is not considered async-signal-safe.<\/i><\/span><\/p>\n<p>Researchers have found that approximately 10,000 attempts are needed to successfully exploit this vulnerability. While the exploit could take days to complete, it is still not guaranteed that the attempt would be successful . The presence of modern security mechanisms such as Address Space Layout Randomization (ASLR) and No-eXecute (NX) bits further complicate the exploitation process but do not entirely mitigate the risk.<\/p>\n<p>Like CVE-2024-6387, this vulnerability occurs when the SSHD\u2019s <i>SIGALRM<\/i> handler is called asynchronously, which in turn calls various functions that are not <i>async-signal-safe<\/i>.<\/p>\n<p>The race condition in <i>grace_alarm_handler()<\/i> calls <i>cleanup_exit()<\/i> from the <i>privsep<\/i> child process. However, <i>cleanup_exit()<\/i> is not designed to be called from a signal handler, potentially invoking unsafe functions. Cleanup function calls can be interrupted by signals, causing unsafe state changes and potential remote code execution (RCE).<\/p>\n<p>As a <i>privsep<\/i> child process run\u2019s with reduced privileges, there is less reason to worry about the vulnerability. In addition, working exploits for the CVE-2024-6409 have not been yet discovered, therefore proof of its actual exploitation has not been established at the time of publishing.<\/p>\n<p>The OpenSSH vendor <a href=\"https:\/\/www.tenable.com\/plugins\/nessus\/201194\">advisory<\/a> mentions that the successful exploitation of CVE-2024-6387 has been demonstrated on 32-bit Linux and GNU C Library (<i>glibc<\/i>) systems with (ASLR). It also mentions that exploitation on 64-bit systems might be possible. However, certain characteristics of X64 systems make this exploitation much more difficult, which we\u2019ll expound on in this section.<\/p>\n<p>In x64 systems, ASLR plays a crucial role by randomizing memory addresses, including those of the GNU C Library (<i>glibc<\/i>), with each program execution. This randomness makes it very difficult for attackers to predict the location of the <i>glibc<\/i> base address, thus mitigating exploits that depend on precise memory targeting. The x64 architecture&#8217;s expansive address space further complicates exploitation, as attackers have to guess an exponentially greater amount of addresses. Combined with security measures such as stack canaries and NX bits, exploiting vulnerabilities such as CVE-2024-6387 becomes highly impractical on x64 systems.<\/p>\n<p>While theoretically possible under specific conditions, the effective implementation of ASLR and the inherent complexities of the x64 environment significantly reduce real-world exploitability, highlighting the robust security benefits of these architectural safeguards.<\/p>\n<p>Our As per our internal telemetry we did not notice any trend change for CVE-2024\u20136387, which could be considered a known exploited vulnerability (KEV)that is being exploited in wild. .<\/p>\n<p>While CVE-2024\u20136387 presents a critical security risk, its real-world impact is mitigated by several factors. The technical complexity of the exploit and the extensive time required to execute it make large-scale attacks impractical. Each attack attempt resets the login timer, requiring precise timing and substantial effort from the attacker.<\/p>\n<p>Moreover, the vulnerability affects specific versions of OpenSSH (up to 4.4p1 and 8.5p1 to 9.7p1) running on Linux systems using the GNU C Library. Systems with additional protections against brute force attacks and distributed denial-of-service (DDoS) are less likely to be successfully exploited. Therefore, while targeted attacks are possible, <b><i>mass exploitation is unlikely<\/i><\/b> due to the unavailability of working exploits and the time required to exploit these vulnerabilities.<\/p>\n<p><span class=\"body-subhead-title\">Mitigation<\/span><\/p>\n<p>To mitigate the risks associated with CVE-2024\u20136387, administrators should immediately update OpenSSH to version 9.8 or later. If immediate updating is not feasible, reducing the <i>LoginGraceTime<\/i> can provide temporary mitigation against this vulnerability.<\/p>\n<p>Additionally, organizations can consider implementing the following best practices for general vulnerability exploit protection:<\/p>\n<p><b>Patch management<br \/><\/b>Regularly updating and patching software, operating systems, and applications is the most straightforward method for organizations to avoid the exploitation of vulnerabilities within their systems.<b><\/b><\/p>\n<p><b>Network segmentation<\/b><br \/>Separating critical network segments from the larger network can minimize the impact of a potential vulnerability exploitation.<\/p>\n<p><b>Regular security audits<\/b><br \/>Performing security audits and vulnerability assessments can identify and remediate potential weaknesses within the infrastructure before they can be exploited.<\/p>\n<p><b>Security awareness training<\/b><br \/>Educating employees about the common tactics used by attackers can help them avoid falling victim to social engineering attacks that might precede vulnerability exploitation.<\/p>\n<p><b>Incident response plan<\/b><br \/>Developing, testing, and maintaining an incident response plan can help organizations quickly and effectively respond to security breaches and vulnerability exploitations.<\/p>\n<p>Additionally, employing network-based access controls, intrusion prevention systems such as <a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/hybrid-cloud.html\">Trend Cloud One\u2122<\/a>, and regular vulnerability scanning can further enhance security.<br \/>For Trend customers, the following IPS smart rules can detect the attack on a surface level:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">1003593 Detected SSH Server Traffic (ATT&amp;CK T1021.004)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">1005748 Multiple SSH Connection Detected (ATT&amp;CK T1499.002, T1110)<\/span><\/li>\n<\/ul>\n<p>According to <a href=\"https:\/\/www.kaspersky.com\/blog\/cve-2024-6387-regresshion-researcher-attack\/51646\/\">other researchers<\/a>, there could be non-functional exploits in circulation that claim to be working proofs-of-concept (POCs) for CVE-2024-6387. These fake exploits contain payloads that download files from remote servers and establish persistence on the systems of security researchers. Assuming they are testing a legitimate POC for the vulnerability, the security features of their systems might be disabled, making them vulnerable to malicious activities.<\/p>\n<p>Overall, while CVE-2024\u20136387 and CVE-2024-6409 is a critical vulnerability, it does not pose a widespread threat to the internet due to its exploitation complexity and existing mitigations. However, administrators should remain vigilant, apply patches promptly, and implement recommended security practices to protect their systems.<\/p>\n<p> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/24\/g\/cve-2024-6387-and-cve-2024-6409.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We check the OpenSSH vulnerabilities CVE-2024\u20136387 and CVE-2024-6409, examining their potential real-world impact and the possibility of exploitation for CVE-2024\u20136387 in x64 systems. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":56597,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9511,9555,9509],"class_list":["post-56596","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-cyber-threats","tag-trend-micro-research-exploitsvulnerabilities","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>The Potential Impact of the OpenSSH Vulnerabilities CVE-2024\u20136387 and CVE-2024-6409 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Potential Impact of the OpenSSH Vulnerabilities CVE-2024\u20136387 and CVE-2024-6409 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2024-07-17T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/cve-2024-6387:Large?qlt=80\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"The Potential Impact of the OpenSSH Vulnerabilities CVE-2024\u20136387 and CVE-2024-6409\",\"datePublished\":\"2024-07-17T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\\\/\"},\"wordCount\":1155,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409.png\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Cyber Threats\",\"Trend Micro Research : Exploits&amp;Vulnerabilities\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\\\/\",\"name\":\"The Potential Impact of the OpenSSH Vulnerabilities CVE-2024\u20136387 and CVE-2024-6409 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409.png\",\"datePublished\":\"2024-07-17T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409.png\",\"width\":976,\"height\":533},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"The Potential Impact of the OpenSSH Vulnerabilities CVE-2024\u20136387 and CVE-2024-6409\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The Potential Impact of the OpenSSH Vulnerabilities CVE-2024\u20136387 and CVE-2024-6409 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\/","og_locale":"en_US","og_type":"article","og_title":"The Potential Impact of the OpenSSH Vulnerabilities CVE-2024\u20136387 and CVE-2024-6409 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2024-07-17T00:00:00+00:00","og_image":[{"url":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/cve-2024-6387:Large?qlt=80","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"The Potential Impact of the OpenSSH Vulnerabilities CVE-2024\u20136387 and CVE-2024-6409","datePublished":"2024-07-17T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\/"},"wordCount":1155,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/07\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409.png","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Cyber Threats","Trend Micro Research : Exploits&amp;Vulnerabilities","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\/","url":"https:\/\/www.threatshub.org\/blog\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\/","name":"The Potential Impact of the OpenSSH Vulnerabilities CVE-2024\u20136387 and CVE-2024-6409 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/07\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409.png","datePublished":"2024-07-17T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/07\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/07\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409.png","width":976,"height":533},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/the-potential-impact-of-the-openssh-vulnerabilities-cve-2024-6387-and-cve-2024-6409\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"The Potential Impact of the OpenSSH Vulnerabilities CVE-2024\u20136387 and CVE-2024-6409"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/56596","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=56596"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/56596\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/56597"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=56596"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=56596"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=56596"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}