Support Center > 详细页 > 安全公告详细

Security Advisory - Security updates related to OpenSSH RCE vulnerability in some products of KAYTUS

  • SA No KAYTUS-SA-2024-002
  • Initial Release Date 2024-09-09 14:46:13
  • last Release Date 2024-10-31 10:36:40
  • Source OpenSSh Security Advisory
  • Potential Security Impact RCE
Vulnerability Summary

CVE-2024-6387, dubbed regreSSHion, has been identified in the OpenSSH server. This vulnerability enables remote unauthenticated attackers to execute arbitrary code on the target server, presenting a severe risk to systems that utilize OpenSSH for secure communications. 

Vulnerability Scoring Details
CVE V3.1 Vector(Base) Base Score V3.1 Vector(Temporal Score) Temporal Score
CVE-2024-6387 AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H 8.1 E:P/RL:O/RC:C 7.3

Fixed Product Version
Products FW UpdateVersion
KR2280X2 KR2280X2_BMC_5.08.05
KR2460X2 KR2460X2_BMC_5.08.05
KR4480X2 KR4480X2_BMC_5.08.05
KR2266X2 KR2266X2_BMC_5.08.00
KR4266X2 KR4266X2_BMC_5.08.05
KR6298X2 KR6298X2_BMC_5.08.06
KR1270X2 KR1270X2_BMC_5.08.05
K24X2 K24X2_BMC_5.08.00
KR6288X2 KR6288X2_BMC_5.08.06
KR4268X2 KR4268X2_BMC_5.08.06

Resolution

Please visit the support center directly to obtain patches and related technical support.

Revision History

2024-09-09 V1.0 INITIAL

References
Support

For issues about implementing the recommendations of this Security Bulletin, contact normal KAYTUS Services Support channel. For other issues about the content of this Security Bulletin, send e-mail to sec@kaytus.com.

Report

To report a potential security vulnerability for KAYTUS product: Reporting a Security Vulnerability

Declaration

KAYTUS shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, KAYTUS disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement. In no event shall KAYTUS or any of its directly or indirectly controlled subsidiaries or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. Your use of the document, by whatsoever means, will be totally at your own risk. KAYTUS is entitled to amend or update this document from time to time.