Chile alerts on OpenSSH CVE-2024-6387
CSIRT Chile warned about critical OpenSSH flaw CVE-2024-6387 and confirmed active exploitation. Patch or mitigate now.
Chile’s government CSIRT issued a security advisory on the critical OpenSSH vulnerability CVE-2024-6387, known as regressh, and said public reports confirm active exploitation. The official guidance is to update to patched versions or apply configuration mitigations.
Official advisory in Chile
Chile’s government CSIRT published a security advisory on the critical OpenSSH vulnerability CVE-2024-6387, known as regressh. In its notice, the team said there is confirmed active exploitation based on public reports and urged organizations to take mitigation measures as soon as possible.
The official recommendation points to two paths, updating to patched versions or applying configuration mitigations. The Chilean alert joins other warnings issued by response teams and coordination bodies that have been tracking the issue since the flaw was disclosed.
What is known about the flaw
CVE-2024-6387 affects OpenSSH and was identified in the sshd component. The CERT Coordination Center reference itself describes it as a vulnerability in the sshd signal handler. OpenSSH included fixes in its 9.8 release notes, and the issue also appears in CISA’s Known Exploited Vulnerabilities catalog.
Qualys published a specific advisory on regressh, while Debian issued DSA-5706-1 with measures for its packages. The fact that the case appears in CISA’s KEV catalog reinforces that it is being tracked because of active exploitation.
Warnings across the region
Chile is not the only regional alert tied to OpenSSH. CERT-MX and CERT.br also issued advisories on CVE-2024-6387, aligned with the need to prioritize remediation in exposed environments.
The focus of these warnings is on servers and services that rely heavily on OpenSSH across critical and corporate infrastructure. In the materials available, the priority set by the agencies is the same, reduce exposure through updating or configuration mitigations while the risk remains.
Sources
- OpenSSH 9.8 release notes (CVE-2024-6387)openssh.com· OpenSSH
- Vulnerabilidad crítica en OpenSSH (CVE-2024-6387)csirt.gob.cl· CSIRT de Gobierno de ChileUnverified URL
- Vulnerabilidades críticas en VMware vCenter Server (CVE-2024-22274, CVE-2024-22275)csirt.gob.cl· CSIRT de Gobierno de ChileUnverified URL
- FG-IR-24-074 FortiOS & FortiProxy Vulnerabilities (CVE-2024-25170)fortiguard.com· Fortinet
- Vulnerabilidades en Cisco IOS XE – recordatorio sobre CVE-2023-20198csirt.gob.cl· CSIRT de Gobierno de ChileUnverified URL
- Cisco IOS XE Software Web UI Privilege Escalation Vulnerability (CVE-2023-20198)sec.cloudapps.cisco.com· Cisco
- GitLab critical security release addressing CVE-2024-7917about.gitlab.com· GitLab
- Vulnerabilidad crítica en GitLab (CVE-2024-7917)csirt.gob.cl· CSIRT de Gobierno de ChileUnverified URL
- Known Exploited Vulnerabilities Catalog entry for CVE-2024-6387 (OpenSSH)cisa.gov· CISA
- Debian Security Advisory DSA-5706-1 for OpenSSHdebian.org· Debian
- KEV Catalog entry for VMware vCenter Server vulnerabilities including CVE-2024-22274cisa.gov· CISA
- KEV Catalog entry for Fortinet FortiOS SSL VPN vulnerability CVE-2024-25170cisa.gov· CISA
- KEV Catalog entry for Cisco IOS XE vulnerability CVE-2023-20198cisa.gov· CISA
- Vulnerability report and campaign analysis for IOS XE exploitationtalosintelligence.com· Cisco Talos
- KEV Catalog entry for GitLab RCE vulnerability CVE-2024-7917cisa.gov· CISA
- Analysis of Fortinet VPN exploitation campaignsmandiant.com· Mandiant



