<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:00:54.977563+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/2nga002427</id>
    <title>2NGA002427 — ABB Arctic ARG600, ARC600, ARR600, ARP600 Arctic Wireless Gateway Modem Module and OpenSSH vulnerabilities</title>
    <updated>2026-10-02T13:00:55.483283+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ABB is aware of public reports of the vulnerabilities in the product versions listed as affected in this advisory.
An attacker who successfully exploited modem module vulnerabilities could run arbitrary code in the wireless modem module of the product. This could lead to denial of service or tampering with unencrypted traffic.
An attacker who successfully exploited the OpenSSH vulnerability could run arbitrary code in the product with privileged user permissions. This could cause the product to stop, make the product inaccessible, or the attacker could take control of the product.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/2nga002427"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:4312</id>
    <title>ALSA-2024:4312 — Important: openssh security update</title>
    <updated>2026-10-02T13:00:55.483366+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: openssh, AlmaLinux:9: openssh-askpass, AlmaLinux:9: openssh-clients, AlmaLinux:9: openssh-keycat, AlmaLinux:9: openssh-server, AlmaLinux:9: pam_ssh_agent_auth</p>
<p>OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.</p>
<p>Security Fix(es):</p>
<p>* openssh: Possible remote code execution due to a race condition in signal handling (CVE-2024-6387)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:4312"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-04914</id>
    <title>bdu:2024-04914</title>
    <updated>2026-10-02T13:00:55.483406+00:00</updated>
    <content>bdu:2024-04914</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-04914"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-6387</id>
    <title>BELL-CVE-2024-6387</title>
    <updated>2026-10-02T13:00:55.483422+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: openssh, Alpaquita:stream: openssh, BellSoft Hardened Containers:23: openssh, BellSoft Hardened Containers:stream: openssh</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-6387"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-ale-009</id>
    <title>certfr-2024-ale-009 — Le 1 juillet 2024, OpenSSH a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-6387.

Cette vuln…</title>
    <updated>2026-10-02T13:00:55.483443+00:00</updated>
    <content>certfr-2024-ale-009</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-ale-009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0531</id>
    <title>certfr-2024-avi-0531 — De multiples vulnérabilités ont été découvertes dans OpenSSH. Elles permettent à un attaquant de provoquer une exécutio…</title>
    <updated>2026-10-02T13:00:55.483464+00:00</updated>
    <content>certfr-2024-avi-0531</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0531"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cisco-sa-openssh-rce-2024</id>
    <title>cisco-sa-openssh-rce-2024 — Remote Unauthenticated Code Execution Vulnerability in OpenSSH Server (regreSSHion): July 2024</title>
    <updated>2026-10-02T13:00:55.483483+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>On July 1, 2024, the Qualys Threat Research Unit (TRU) disclosed an unauthenticated, remote code execution vulnerability that affects the OpenSSH server (sshd) in glibc-based Linux systems.

CVE-2024-6387: A signal handler race condition was found in sshd, where a client does not authenticate within LoginGraceTime seconds (120 by default, 600 in old OpenSSH versions), then the sshd SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog().

For a description of this vulnerability, see the Qualys Security Advisory ["https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt"].</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cisco-sa-openssh-rce-2024"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2024-29805</id>
    <title>cnvd-2024-29805</title>
    <updated>2026-10-02T13:00:55.483508+00:00</updated>
    <content>cnvd-2024-29805</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2024-29805"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-362203</id>
    <title>EUVD-2026-362203</title>
    <updated>2026-10-02T13:00:55.483520+00:00</updated>
    <content>EUVD-2026-362203</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-362203"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-6387</id>
    <title>fkie_cve-2024-6387</title>
    <updated>2026-10-02T13:00:55.483530+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-6387"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2x8c-95vh-gfv4</id>
    <title>GHSA-2x8c-95vh-gfv4</title>
    <updated>2026-10-02T13:00:55.483552+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A signal handler race condition was found in OpenSSH's server (sshd), where a client does not authenticate within LoginGraceTime seconds (120 by default, 600 in old OpenSSH versions), then sshd's SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog().</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2x8c-95vh-gfv4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-24-256-15</id>
    <title>ICSA-24-256-15 — Siemens Industrial Products</title>
    <updated>2026-10-02T13:00:55.483567+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead to sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-24-256-15"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1781</id>
    <title>OESA-2024-1781 — openssh security update</title>
    <updated>2026-10-02T13:00:55.483584+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: openssh</p>
<p>OpenSSH is the premier connectivity tool for remote login with the SSH protocol. \ It encrypts all traffic to eliminate eavesdropping, connection hijacking, and \ other attacks. In addition, OpenSSH provides a large suite of secure tunneling \ capabilities, several authentication methods, and sophisticated configuration options.

Security Fix(es):

A signal handler race condition was found in OpenSSH&amp;apos;s server (sshd), where a client does not authenticate within LoginGraceTime seconds (120 by default, 600 in old OpenSSH versions), then sshd&amp;apos;s SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog().(CVE-2024-6387)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1781"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14088-1</id>
    <title>openSUSE-SU-2024:14088-1 — openssh-9.6p1-10.1 on GA media</title>
    <updated>2026-10-02T13:00:55.483606+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openssh-9.6p1-10.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14088-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:4340</id>
    <title>RHSA-2024:4340 — Red Hat Security Advisory: openssh security update</title>
    <updated>2026-10-02T13:00:55.483621+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openssh: regreSSHion - race condition in SSH allows RCE/DoS</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:4340"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-082556</id>
    <title>SSA-082556 — SSA-082556: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5</title>
    <updated>2026-10-02T13:00:55.483637+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p>
<p>Note: This SSA advises vulnerabilities for firmware version V3.1.5 only; for version V3.1.6 refer to SSA-019113.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-082556"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:2275-1</id>
    <title>SUSE-SU-2024:2275-1 — Security update for openssh</title>
    <updated>2026-10-02T13:00:55.483807+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssh</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:2275-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-6387</id>
    <title>UBUNTU-CVE-2024-6387</title>
    <updated>2026-10-02T13:00:55.483821+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: openssh, Ubuntu:24.04:LTS: openssh</p>
<p>A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-6387"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-040</id>
    <title>VDE-2024-040 — Multiple TRUMPF products prone to regreSSHion OpenSSH server vulnerabilities</title>
    <updated>2026-10-02T13:00:55.483842+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>TruControl laser control software prior to version 1.60.0 uses an OpenSSH server version affected by CVE-2024-6387. The affected OpenSSH Server version could potentially lead to a remote code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-040"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-042</id>
    <title>VDE-2024-042 — MB connect line: Multiple products are vulnerable to regreSSHion</title>
    <updated>2026-10-02T13:00:55.483857+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several Red Lion Europe products are vulnerable to a possible race condition vulnerability in OpenSSH named "regreSSHion".</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-042"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-043</id>
    <title>VDE-2024-043 — Welotec: Multiple products are vulnerable to regreSSHion</title>
    <updated>2026-10-02T13:00:55.483872+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Products from the Edge Gateway Family are affected by recently published so called RegreSSHion vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-043"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-044</id>
    <title>VDE-2024-044 — Helmholz: Multiple products are vulnerable to regreSSHion</title>
    <updated>2026-10-02T13:00:55.483886+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several Helmholz products are vulnerable to a possible race condition vulnerability in OpenSSH named "regreSSHion".</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-044"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-051</id>
    <title>VDE-2024-051 — Phoenix Contact: Multiple mGuard devices are vulnerable to a remote code injection due to SSH</title>
    <updated>2026-10-02T13:00:55.483901+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>mGuards use an OpenSSH server for SSH access. This server is vulnerable to a remote code injection.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-051"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-063</id>
    <title>VDE-2024-063 — PEPPERL+FUCHS: Multiple products are affected by regreSSHion</title>
    <updated>2026-10-02T13:00:55.483915+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The affected devices run a SSH server that is affected by the regreSSHion vulnerability despite the fact that no user can actually log in through SSH. Attackers may exploit this vulnerability to gain root access to the device.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-063"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1486</id>
    <title>WID-SEC-W-2024-1486 — OpenSSH: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-02T13:00:55.483930+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in OpenSSH ausnutzen, um beliebigen Programmcode mit root Rechten auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1486"/>
  </entry>
</feed>
