OpenSSH vulnerability CVE-2024-6387
Introduction
This page aims to inform about the critical vulnerability identified in the OpenSSH server (CVE-2024-6387). It affects all VPS instances and templates within the SERVERware environment using the affected version of OpenSSH.
Vulnerability details
Description
The identified vulnerability could allow attackers to gain unauthorized access and execute arbitrary code on the affected servers. Given the severity of this issue, immediate action is required to protect our systems and your operations.
Affected versions
Full details about the OpenSSH versions affected by this vulnerability can be found in the post on this link
Development of a fix
Our team is actively working on researching and developing a fix for this vulnerability. All Bicom Systems hosted partners can rest assured that our team is inspecting and applying the necessary fix to all affected VPS instances.
IMPORTANT NOTE:
After applying the patch, the sshd server will remain vulnerable to denial-of-service (DoS) attacks due to the possibility of MaxStartups connection exhaustion. However, it will be protected against potential remote code execution attacks.

