<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:02:00 +0000</lastBuildDate>
    <item>
      <title>2NGA002427 — ABB Arctic ARG600, ARC600, ARR600, ARP600 Arctic Wireless Gateway Modem Module and OpenSSH vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/2nga002427</link>
      <description>&lt;p&gt;ABB is aware of public reports of the vulnerabilities in the product versions listed as affected in this advisory.
An attacker who successfully exploited modem module vulnerabilities could run arbitrary code in the wireless modem module of the product. This could lead to denial of service or tampering with unencrypted traffic.
An attacker who successfully exploited the OpenSSH vulnerability could run arbitrary code in the product with privileged user permissions. This could cause the product to stop, make the product inaccessible, or the attacker could take control of the product.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB is aware of public reports of the vulnerabilities in the product versions listed as affected in this advisory.
An attacker who successfully exploited modem module vulnerabilities could run arbitrary code in the wireless modem module of the product. This could lead to denial of service or tampering with unencrypted traffic.
An attacker who successfully exploited the OpenSSH vulnerability could run arbitrary code in the product with privileged user permissions. This could cause the product to stop, make the product inaccessible, or the attacker could take control of the product.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/2nga002427</guid>
    </item>
    <item>
      <title>ALSA-2024:4312 — Important: openssh security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:4312</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: openssh, AlmaLinux:9: openssh-askpass, AlmaLinux:9: openssh-clients, AlmaLinux:9: openssh-keycat, AlmaLinux:9: openssh-server, AlmaLinux:9: pam_ssh_agent_auth&lt;/p&gt;
&lt;p&gt;OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssh: Possible remote code execution due to a race condition in signal handling (CVE-2024-6387)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: openssh, AlmaLinux:9: openssh-askpass, AlmaLinux:9: openssh-clients, AlmaLinux:9: openssh-keycat, AlmaLinux:9: openssh-server, AlmaLinux:9: pam_ssh_agent_auth&lt;/p&gt;
&lt;p&gt;OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssh: Possible remote code execution due to a race condition in signal handling (CVE-2024-6387)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:4312</guid>
    </item>
    <item>
      <title>bdu:2024-04914</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-04914</link>
      <description>bdu:2024-04914</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-04914</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-6387</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-6387</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: openssh, Alpaquita:stream: openssh, BellSoft Hardened Containers:23: openssh, BellSoft Hardened Containers:stream: openssh&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: openssh, Alpaquita:stream: openssh, BellSoft Hardened Containers:23: openssh, BellSoft Hardened Containers:stream: openssh&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-6387</guid>
    </item>
    <item>
      <title>certfr-2024-ale-009 — Le 1 juillet 2024, OpenSSH a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-6387.

Cette vuln…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-ale-009</link>
      <description>certfr-2024-ale-009</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-ale-009</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0531 — De multiples vulnérabilités ont été découvertes dans OpenSSH. Elles permettent à un attaquant de provoquer une exécutio…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0531</link>
      <description>certfr-2024-avi-0531</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0531</guid>
    </item>
    <item>
      <title>cisco-sa-openssh-rce-2024 — Remote Unauthenticated Code Execution Vulnerability in OpenSSH Server (regreSSHion): July 2024</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-openssh-rce-2024</link>
      <description>&lt;p&gt;On July 1, 2024, the Qualys Threat Research Unit (TRU) disclosed an unauthenticated, remote code execution vulnerability that affects the OpenSSH server (sshd) in glibc-based Linux systems.&#13;
&#13;
CVE-2024-6387: A signal handler race condition was found in sshd, where a client does not authenticate within LoginGraceTime seconds (120 by default, 600 in old OpenSSH versions), then the sshd SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog().&#13;
&#13;
For a description of this vulnerability, see the Qualys Security Advisory [&amp;#34;https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt&amp;#34;].&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;On July 1, 2024, the Qualys Threat Research Unit (TRU) disclosed an unauthenticated, remote code execution vulnerability that affects the OpenSSH server (sshd) in glibc-based Linux systems.&#13;
&#13;
CVE-2024-6387: A signal handler race condition was found in sshd, where a client does not authenticate within LoginGraceTime seconds (120 by default, 600 in old OpenSSH versions), then the sshd SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog().&#13;
&#13;
For a description of this vulnerability, see the Qualys Security Advisory [&amp;#34;https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt&amp;#34;].&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-openssh-rce-2024</guid>
    </item>
    <item>
      <title>cnvd-2024-29805</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2024-29805</link>
      <description>cnvd-2024-29805</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2024-29805</guid>
    </item>
    <item>
      <title>EUVD-2026-362203</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-362203</link>
      <description>EUVD-2026-362203</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-362203</guid>
    </item>
    <item>
      <title>fkie_cve-2024-6387</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-6387</link>
      <description>&lt;p&gt;A security regression (CVE-2006-5051) was discovered in OpenSSH&amp;#39;s server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A security regression (CVE-2006-5051) was discovered in OpenSSH&amp;#39;s server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-6387</guid>
    </item>
    <item>
      <title>GHSA-2x8c-95vh-gfv4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2x8c-95vh-gfv4</link>
      <description>&lt;p&gt;A signal handler race condition was found in OpenSSH&amp;#39;s server (sshd), where a client does not authenticate within LoginGraceTime seconds (120 by default, 600 in old OpenSSH versions), then sshd&amp;#39;s SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog().&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A signal handler race condition was found in OpenSSH&amp;#39;s server (sshd), where a client does not authenticate within LoginGraceTime seconds (120 by default, 600 in old OpenSSH versions), then sshd&amp;#39;s SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog().&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2x8c-95vh-gfv4</guid>
    </item>
    <item>
      <title>ICSA-24-256-15 — Siemens Industrial Products</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-256-15</link>
      <description>&lt;p&gt;A security regression (CVE-2006-5051) was discovered in OpenSSH&amp;#39;s server (sshd). There is a race condition which can lead to sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A security regression (CVE-2006-5051) was discovered in OpenSSH&amp;#39;s server (sshd). There is a race condition which can lead to sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-256-15</guid>
    </item>
    <item>
      <title>OESA-2024-1781 — openssh security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1781</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: openssh&lt;/p&gt;
&lt;p&gt;OpenSSH is the premier connectivity tool for remote login with the SSH protocol. \ It encrypts all traffic to eliminate eavesdropping, connection hijacking, and \ other attacks. In addition, OpenSSH provides a large suite of secure tunneling \ capabilities, several authentication methods, and sophisticated configuration options.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A signal handler race condition was found in OpenSSH&amp;amp;apos;s server (sshd), where a client does not authenticate within LoginGraceTime seconds (120 by default, 600 in old OpenSSH versions), then sshd&amp;amp;apos;s SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog().(CVE-2024-6387)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: openssh&lt;/p&gt;
&lt;p&gt;OpenSSH is the premier connectivity tool for remote login with the SSH protocol. \ It encrypts all traffic to eliminate eavesdropping, connection hijacking, and \ other attacks. In addition, OpenSSH provides a large suite of secure tunneling \ capabilities, several authentication methods, and sophisticated configuration options.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A signal handler race condition was found in OpenSSH&amp;amp;apos;s server (sshd), where a client does not authenticate within LoginGraceTime seconds (120 by default, 600 in old OpenSSH versions), then sshd&amp;amp;apos;s SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog().(CVE-2024-6387)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1781</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14088-1 — openssh-9.6p1-10.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14088-1</link>
      <description>&lt;p&gt;openssh-9.6p1-10.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssh-9.6p1-10.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14088-1</guid>
    </item>
    <item>
      <title>RHSA-2024:4340 — Red Hat Security Advisory: openssh security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:4340</link>
      <description>&lt;p&gt;openssh: regreSSHion - race condition in SSH allows RCE/DoS&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssh: regreSSHion - race condition in SSH allows RCE/DoS&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:4340</guid>
    </item>
    <item>
      <title>SSA-082556 — SSA-082556: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-082556</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;
&lt;p&gt;Note: This SSA advises vulnerabilities for firmware version V3.1.5 only; for version V3.1.6 refer to SSA-019113.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;
&lt;p&gt;Note: This SSA advises vulnerabilities for firmware version V3.1.5 only; for version V3.1.6 refer to SSA-019113.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-082556</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2275-1 — Security update for openssh</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2275-1</link>
      <description>&lt;p&gt;Security update for openssh&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for openssh&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2275-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-6387</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-6387</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: openssh, Ubuntu:24.04:LTS: openssh&lt;/p&gt;
&lt;p&gt;A security regression (CVE-2006-5051) was discovered in OpenSSH&amp;#39;s server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: openssh, Ubuntu:24.04:LTS: openssh&lt;/p&gt;
&lt;p&gt;A security regression (CVE-2006-5051) was discovered in OpenSSH&amp;#39;s server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-6387</guid>
    </item>
    <item>
      <title>VDE-2024-040 — Multiple TRUMPF products prone to regreSSHion OpenSSH server vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-040</link>
      <description>&lt;p&gt;TruControl laser control software prior to version 1.60.0 uses an OpenSSH server version affected by CVE-2024-6387. The affected OpenSSH Server version could potentially lead to a remote code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;TruControl laser control software prior to version 1.60.0 uses an OpenSSH server version affected by CVE-2024-6387. The affected OpenSSH Server version could potentially lead to a remote code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-040</guid>
    </item>
    <item>
      <title>VDE-2024-042 — MB connect line: Multiple products are vulnerable to regreSSHion</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-042</link>
      <description>&lt;p&gt;Several Red Lion Europe products are vulnerable to a possible race condition vulnerability in OpenSSH named &amp;#34;regreSSHion&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several Red Lion Europe products are vulnerable to a possible race condition vulnerability in OpenSSH named &amp;#34;regreSSHion&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-042</guid>
    </item>
    <item>
      <title>VDE-2024-043 — Welotec: Multiple products are vulnerable to regreSSHion</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-043</link>
      <description>&lt;p&gt;Products from the Edge Gateway Family are affected by recently published so called RegreSSHion vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Products from the Edge Gateway Family are affected by recently published so called RegreSSHion vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-043</guid>
    </item>
    <item>
      <title>VDE-2024-044 — Helmholz: Multiple products are vulnerable to regreSSHion</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-044</link>
      <description>&lt;p&gt;Several Helmholz products are vulnerable to a possible race condition vulnerability in OpenSSH named &amp;#34;regreSSHion&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several Helmholz products are vulnerable to a possible race condition vulnerability in OpenSSH named &amp;#34;regreSSHion&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-044</guid>
    </item>
    <item>
      <title>VDE-2024-051 — Phoenix Contact: Multiple mGuard devices are vulnerable to a remote code injection due to SSH</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-051</link>
      <description>&lt;p&gt;mGuards use an OpenSSH server for SSH access. This server is vulnerable to a remote code injection.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;mGuards use an OpenSSH server for SSH access. This server is vulnerable to a remote code injection.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-051</guid>
    </item>
    <item>
      <title>VDE-2024-063 — PEPPERL+FUCHS: Multiple products are affected by regreSSHion</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-063</link>
      <description>&lt;p&gt;The affected devices run a SSH server that is affected by the regreSSHion vulnerability despite the fact that no user can actually log in through SSH. Attackers may exploit this vulnerability to gain root access to the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected devices run a SSH server that is affected by the regreSSHion vulnerability despite the fact that no user can actually log in through SSH. Attackers may exploit this vulnerability to gain root access to the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-063</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1486 — OpenSSH: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1486</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in OpenSSH ausnutzen, um beliebigen Programmcode mit root Rechten auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in OpenSSH ausnutzen, um beliebigen Programmcode mit root Rechten auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1486</guid>
    </item>
  </channel>
</rss>
