{"id":85863,"date":"2024-07-02T10:48:11","date_gmt":"2024-07-02T10:48:11","guid":{"rendered":"https:\/\/news.talkwithrattan.com\/index.php\/2024\/07\/02\/openssh-vulnerability-reportedly-puts-over-14-million-servers-at-risk\/"},"modified":"2024-07-02T10:48:11","modified_gmt":"2024-07-02T10:48:11","slug":"openssh-vulnerability-reportedly-puts-over-14-million-servers-at-risk","status":"publish","type":"post","link":"https:\/\/news.talkwithrattan.com\/index.php\/2024\/07\/02\/openssh-vulnerability-reportedly-puts-over-14-million-servers-at-risk\/","title":{"rendered":"OpenSSH Vulnerability Reportedly Puts Over 14 Million Servers at Risk"},"content":{"rendered":"<div style=\"text-align:center\"><img loading=\"lazy\" decoding=\"async\" width=\"1\" height=\"1\" src=\"https:\/\/i0.wp.com\/www.gadgets360.com\/static\/desktop\/images\/spacer.png?fit=1,1&amp;ssl=1\" class=\"attachment-post-thumbnail size-post-thumbnail wp-post-image\" alt=\"OpenSSH Vulnerability Reportedly Puts Over 14 Million Servers at Risk\" title=\"OpenSSH Vulnerability Reportedly Puts Over 14 Million Servers at Risk\" \/><\/div><p> <br \/>\n<\/p>\n<div id=\"center_content_div\">\n<div class=\"content_text row description\">\n<p>OpenSSH servers in large numbers are reportedly affected by a newly discovered vulnerability. This vulnerability is said to be a regression of a previously patched vulnerability that has resurfaced. As per the report, more than 14 million servers were found to be at risk, particularly those with versions earlier than 4.4p1 can be affected by this vulnerability dubbed regreSSHion. This regression was reportedly introduced in October 2020 (OpenSSH 8.5p1). The vulnerability has been labelled and is being tracked as CVE-2024-6387.<\/p>\n<h2 id=\"researchers-identify-major-openssh-vulnerability\">Researchers identify major OpenSSH vulnerability<\/h2>\n<p>Cybersecurity firm Qualys, which discovered the vulnerability, said in a <a href=\"https:\/\/blog.qualys.com\/vulnerabilities-threat-research\/2024\/07\/01\/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server\" target=\"_blank\" rel=\"nofollow noopener\">post<\/a> that CVE-2024-6387 is a remote unauthenticated code execution (RCE) vulnerability in OpenSSH&#8217;s server (sshd). OpenSSH, also referred to as OpenBSD Secure Shell (SSH), is a suite of tools that facilitate secure communication over a network. It is a widely implemented SSH protocol that provides a safe encrypted channel over an unsecured network. The system is used for both internal networks as well as over the Internet.<\/p>\n<p>During the investigation, the cybersecurity firm reportedly found more than 14 million potentially vulnerable OpenSSH server instances that were exposed to the Internet. Among them, there were reportedly 7,00,000 external internet-facing instances that were vulnerable to the condition. This high number of exposed servers highlights the scale of risk these systems face.<\/p>\n<p>As per the report, the current vulnerability is a regression of a previously patched vulnerability from 2006 dubbed CVE-2006-5051, which is why it is also being called regreSSHion. An attacker can hypothetically execute arbitrary code with the highest privileges and compromise the entire system due to this vulnerability. Further threat actors can also bypass critical security mechanisms to gain root access to the impacted server.<\/p>\n<p>However, Qualys also pointed out that this vulnerability is not easy to exploit due to it being a remote race condition, and it will likely require multiple break-in attempts before an attack results in success.<\/p>\n<p>The cybersecurity firm recommended enterprises using OpenSSH to apply available patches as soon as possible and to prioritise the ongoing update process. Enterprises are also asked to limit SSH access through network-based controls to minimise the attack risks.<\/p>\n<hr\/>\n<div class=\"downloadtxt\"><i>Affiliate links may be automatically generated &#8211; see our <a href=\"https:\/\/www.gadgets360.com\/ethics\" target=\"_blank\" rel=\"noopener\">ethics statement<\/a> for details.<\/i><\/div>\n<\/div>\n<p class=\"downloadtxt margin_b20\">\n                For the latest <a href=\"https:\/\/www.gadgets360.com\/news\">tech news<\/a> and <a href=\"https:\/\/www.gadgets360.com\/reviews\">reviews<\/a>, follow Gadgets 360 on <a href=\"https:\/\/twitter.com\/gadgets360\" target=\"_blank\" rel=\"nofollow noopener\">X<\/a>, <a href=\"https:\/\/facebook.com\/gadgets360\" target=\"_blank\" rel=\"nofollow noopener\">Facebook<\/a>, <a href=\"https:\/\/whatsapp.com\/channel\/0029VaB3o5hHltY9SJbXg335\" target=\"_blank\" rel=\"nofollow noopener\">WhatsApp<\/a>, <a href=\"https:\/\/www.threads.net\/@gadgets.360\" target=\"_blank\" rel=\"nofollow noopener\">Threads<\/a> and <a href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMILm3AowtoHPAQ?hl=en-IN&amp;gl=IN&amp;ceid=IN%3Aen\" target=\"_blank\" rel=\"nofollow noopener\">Google News<\/a>. For the latest videos on gadgets and tech, subscribe to our <a href=\"https:\/\/www.youtube.com\/channel\/UCx5e1u7BX0aKwEj3sdYXdXg?sub_confirmation=1\" target=\"_blank\" rel=\"nofollow noopener\">YouTube channel<\/a>. If you want to know everything about top influencers, follow our in-house <a href=\"https:\/\/www.whosthat360.com\/\" target=\"_blank\" rel=\"noopener\">Who&#8217;sThat360<\/a> on <a href=\"https:\/\/www.instagram.com\/whosthat360\/\" target=\"_blank\" rel=\"nofollow noopener\">Instagram<\/a> and <a href=\"https:\/\/www.youtube.com\/@WhosThat360\" target=\"_blank\" rel=\"nofollow noopener\">YouTube<\/a>.            <\/p>\n<div class=\"story_nextprv\">\n<div class=\"left_story\">\n            <a href=\"https:\/\/www.gadgets360.com\/cryptocurrency\/news\/mudrex-koinx-partnership-process-crypto-taxes-india-users-6017376\"><br \/>\n                <i class=\"sprite\"\/><\/p>\n<div class=\"story_image\"><\/div>\n<p>                <span>Mudrex, KoinX Partner to Process Crypto Taxes for Users in India<\/span><br \/>\n            <\/a>\n        <\/div>\n<\/div>\n<p>    <!--\n\n<div class=\"adhead\">\n    <span>Advertisement<\/span>\n    \n\n<div id='div-gpt-ad-1667475893419-0' style=\"min-width: 728px; min-height: 90px; text-align:center;\">\n        \n    <\/div>\n\n\n<\/div>\n\n--><\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><script async src=\"\/\/www.instagram.com\/embed.js\"><\/script><br \/>\n<br \/><br \/>\n<br \/><a href=\"https:\/\/www.gadgets360.com\/internet\/news\/openssh-vulnerability-regresshion-identified-14-million-servers-at-risk-report-6017417#rss-gadgets-news\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>OpenSSH servers in large numbers are reportedly affected by a newly discovered vulnerability. This vulnerability is said to be a regression of a previously patched vulnerability that has resurfaced. As per the report, more than 14 million servers were found to be at risk, particularly those with versions earlier than 4.4p1 can be affected by [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":85864,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"tdm_status":"","tdm_grid_status":"","fifu_image_url":"https:\/\/www.gadgets360.com\/static\/desktop\/images\/spacer.png","fifu_image_alt":"","footnotes":""},"categories":[607],"tags":[75058,2600,2458,75059,75057,75056,4357,6128,1115,36875,51879],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/posts\/85863"}],"collection":[{"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/comments?post=85863"}],"version-history":[{"count":1,"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/posts\/85863\/revisions"}],"predecessor-version":[{"id":85865,"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/posts\/85863\/revisions\/85865"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/media\/85864"}],"wp:attachment":[{"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/media?parent=85863"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/categories?post=85863"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news.talkwithrattan.com\/index.php\/wp-json\/wp\/v2\/tags?post=85863"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}