Is UIM is affected by CVE-2024-6387, CVE-2006-5051, CVE-2008-4109?
search cancel

Is UIM is affected by CVE-2024-6387, CVE-2006-5051, CVE-2008-4109?

book

Article ID: 372018

calendar_today

Updated On:

Products

DX Unified Infrastructure Management (Nimsoft / UIM)

Issue/Introduction

Is UIM is affected by CVE-2024-6387, CVE-2006-5051, CVE-2008-4109?

[Background]

On 1 July, Qualys Threat Research Unit (TRU) identified a remote unauthenticated code execution (RCE) vulnerability (CVE-2024-6387), named RegreSSHion in OpenSSH's server (sshd). The vulnerability is a race condition caused by unsafe handling of signal1 when user authentication times out. This race condition affects sshd default configuration. Successful exploitation of this vulnerability could lead to full system compromise where an unauthenticated attacker can perform remote code execution (RCE) with the highest privileges on glibc-based Linux systems.

The vulnerability impacts the following OpenSSH versions on glibc-based Linux systems: 

OpenSSH versions from 8.5p1 to 9.7p1 (inclusive). 
OpenSSH versions earlier than 4.4p1, unless they are patched for CVE-2006-5051 and CVE-2008-4109

 

Environment

UIM all versions

Resolution

 UIM is not affected by these vulnerabilities.