Cyber Security News

Cisco Warns of regreSSHion RCE Impacting Multiple Products

Cisco has issued a security advisory regarding a critical remote code execution (RCE) vulnerability, dubbed “regreSSHion,” that affects multiple products.

The vulnerability tracked as CVE-2024-6387, was disclosed by the Qualys Threat Research Unit on July 1, 2024. It impacts the OpenSSH server (sshd) in glibc-based Linux systems and has the potential to allow unauthenticated attackers to gain root access to affected systems.

Vulnerability Details

The regreSSHion vulnerability is a regression of an older flaw (CVE-2006-5051) that was reintroduced in OpenSSH version 8.5p1, released in October 2020.

Join our free webinar to learn about combating slow DDoS attacks, a major threat today.

The flaw involves a race condition in the sshd’s SIGALRM handler, which calls functions that are not async-signal-safe, such as syslog().

An attacker can exploit this by opening multiple connections and failing to authenticate within the LoginGraceTime period, triggering the vulnerable signal handler asynchronously.

Cisco has identified several products across various categories affected by this vulnerability.

The company is actively investigating its product line to determine the full scope of impacted devices. The following table lists the affected products and their respective Cisco Bug IDs:

Product CategoryProduct NameCisco Bug IDFixed Release Availability
Network and Content Security DevicesAdaptive Security Appliance (ASA) SoftwareCSCwk61618
Firepower Management Center (FMC) SoftwareCSCwk61618
Firepower Threat Defense (FTD) SoftwareCSCwk61618
FXOS Firepower Chassis ManagerCSCwk62297
Identity Services Engine (ISE)CSCwk61938
Secure Network AnalyticsCSCwk62315
Network Management and ProvisioningCrosswork Data GatewayCSCwk623117.0.0 (Aug 2024)
Cyber VisionCSCwk62289
DNA Spaces ConnectorCSCwk62273
Prime InfrastructureCSCwk62276
Smart Software Manager On-PremCSCwk62288
Virtualized Infrastructure ManagerCSCwk62277
Routing and Switching – Enterprise and Service ProviderASR 5000 Series RoutersCSCwk62248
Nexus 3000 Series SwitchesCSCwk61235
Nexus 9000 Series Switches in standalone NX-OS modeCSCwk61235
Unified ComputingIntersight Virtual ApplianceCSCwk63145
Voice and Unified Communications DevicesEmergency ResponderCSCwk63694
Unified Communications ManagerCSCwk62318
Unified Communications Manager IM & Presence ServiceCSCwk63634
Unity ConnectionCSCwk63494
Video, Streaming, TelePresence, and Transcoding DevicesCisco Meeting ServerCSCwk62286SMU – CMS 3.9.2 (Aug 2024)

Mitigation and Recommendations

Cisco recommends several steps to mitigate the risk of exploitation:

  • Restrict SSH Access: Limit SSH access to trusted hosts only. This can be achieved by applying infrastructure access control lists (ACLs) to prevent unauthorized access to SSH services.
  • Upgrade OpenSSH: Upgrade to the latest patched version of OpenSSH (9.8p1) as soon as it becomes available in the package repositories of Linux distributions.
  • Adjust LoginGraceTime: Set the LoginGraceTime parameter to 0 in the sshd configuration file to prevent the race condition, although this may lead to denial-of-service if all connection slots become occupied[1][6][7].

The Cisco Product Security Incident Response Team (PSIRT) knows that a proof-of-concept exploit code is available for this vulnerability. However, the exploitation requires customization, and there have been no reports of malicious use.

Cisco continues to assess all products and services for impact and will update the advisory as new information becomes available.

The regreSSHion vulnerability poses a significant risk to a wide range of Cisco products.

Customers are urged to follow Cisco’s recommendations and apply the necessary patches and mitigations to protect their systems from potential exploitation.

"Is Your System Under Attack? Try Cynet XDR: Automated Detection & Response for Endpoints, Networks, & Users!"- Free Demo

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago