{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3onetappa1k_firmware-/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:sonicwall:sma_6200_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:sonicwall:sma_7200_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:23.10:*:*:*:*:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:24.04:*:*:*:lts:*:*:*","cpe:2.3:o:almalinux:almalinux:9.0:-:*:*:*:*:*:*","cpe:2.3:o:sonicwall:sma_6210_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:sonicwall:sma_7210_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:sonicwall:sma_8200v_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:sonicwall:sra_ex_7000_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:a1k_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:a70_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:a90_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:a700s_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:8300_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:8700_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:a400_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:c400_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:a250_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:500f_firmware:-:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2024-6387"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenSSH"],"_cs_severities":["high"],"_cs_tags":["vulnerability","openssh","rce"],"_cs_type":"advisory","_cs_vendors":["OpenSSH"],"content_html":"\u003cp\u003eOpenSSH has been identified as vulnerable to multiple security flaws that impact its core functionality, potentially allowing unauthorized actors to perform remote code execution (RCE), denial of service (DoS), or security control bypasses. The most critical issue is a signal handler race condition within the sshd server, commonly tracked as regreSSHion (CVE-2024-6387). This vulnerability arises due to the improper handling of signals within the sshd process, which an attacker can trigger remotely to gain unauthorized execution privileges as the root user. Given the ubiquity of OpenSSH in enterprise, cloud, and infrastructure environments, these vulnerabilities pose a significant risk to organizational integrity. Defenders must prioritize identifying and patching affected versions of OpenSSH across all internet-facing and internal Linux/Unix-based servers to mitigate the threat of privilege escalation and system compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows for remote code execution with root privileges, which could result in full system compromise, data exfiltration, lateral movement within the network, or the deployment of persistent threats. Denial of service conditions could lead to significant operational disruption for critical infrastructure relying on SSH for remote administration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all servers running affected versions of OpenSSH and apply vendor patches immediately.\u003c/li\u003e\n\u003cli\u003eReview network access control lists to restrict SSH access only to trusted management IP addresses, reducing the attack surface for potential exploitation.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual sshd process crashes or re-spawns, which can be indicative of race condition exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T11:59:34Z","date_published":"2026-08-11T11:59:34Z","id":"https://feed.craftedsignal.io/briefs/2026-08-openssh-vulnerabilities/","summary":"OpenSSH is susceptible to multiple security flaws, most notably a signal handler race condition in the sshd server known as regreSSHion, which can enable remote code execution with root privileges.","title":"Multiple Vulnerabilities in OpenSSH Including Remote Code Execution","url":"https://feed.craftedsignal.io/briefs/2026-08-openssh-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:netapp:a1k_firmware:-:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}