HPE OneView
1820165 Members
3748 Online
109620 Solutions
New Discussion

HPE Oneview & CVE-2024-6387

 
SOLVED
Go to solution
rdgg
Senior Member

HPE Oneview & CVE-2024-6387

Hi,

How 

CVE-2024-6387
fixed in HPE oneview ?
 
 
--------

Assigner: Red Hat, Inc.

Published: 2024-07-01
Updated: 2024-07-04

Title: Openssh: Possible Remote Code Execution Due To A Race Condition In Signal Handling

Description

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead to sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

----------------------

 

2 REPLIES 2
ManBha
HPE Pro
Solution

Re: HPE Oneview & CVE-2024-6387

Hello,

HPE is aware of CVE-2024-6387 (a.k.a. "regreSSHion"), a signal handling vulnerability in OpenSSH. Most HPE products are not vulnerable to this issue. However, for any affected products, security bulletins will be issued when fixes become available.

https://support.hpe.com/hpesc/public/docDisplay?docId=sd00001284en_us&page=GUID-D9A5A789-A7C0-4250-93FF-04D4FBD2E5A8.html&docLocale=en_US

Thanks.

I work for HPE.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]

Accept or Kudo

DanCernese
HPE Pro

Re: HPE Oneview & CVE-2024-6387

HPE OneView does not use any of the vulnerable versions.  As posted, monitor the official security bulletin status.



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo