Openssh vulnerability CVE-2024-39894 detected on ESXi
search cancel

Openssh vulnerability CVE-2024-39894 detected on ESXi

book

Article ID: 390140

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

CVE-2024-39894 Detail

  • Run command ssh -v command in ESXi shell to check the openssh version

Environment

VMware vSphere ESXi 7.x

Resolution

VMware By Broadcom is aware of CVE-2024-39894.
Please refer to the release notes for existing and forthcoming product releases for any updates in relation to this CVE.
Should you require further information please contact Broadcom Support.