Messaging Gateway Vulnerability Status (CVE-2024-6387)
search cancel

Messaging Gateway Vulnerability Status (CVE-2024-6387)

book

Article ID: 424914

calendar_today

Updated On:

Products

Messaging Gateway

Issue/Introduction

Is Symantec Messaging Gateway (SMG) vulnerable to CVE-2024-6387 (also known as "regreSSHion"), a signal handler race condition in OpenSSH's server (sshd)?

 

Environment

  • Product: Symantec Messaging Gateway (SMG)
  • Versions: 10.9.0, 10.9.1, 10.9.2

Cause

CVE-2024-6387 impacts specific versions of OpenSSH. Security scanners may flag Messaging Gateway if they perform a simple version-string check without verifying backported patches or specific build configurations.

Resolution

Broadcom Engineering has confirmed that Symantec Messaging Gateway (SMG) versions 10.9.0 and later are NOT affected by CVE-2024-6387.