{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination","urls":["https://certvde.com"]}],"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"Several Red Lion Europe products are vulnerable to a possible race condition vulnerability in OpenSSH named \"regreSSHion\".","title":"Summary"},{"category":"description","text":"Possible full system compromise where an attacker can execute arbitrary code with the highest privileges.","title":"Impact"},{"category":"description","text":"Prevent all access to the sshd daemon listening on port 22.","title":"Mitigation"},{"category":"description","text":"Update to latest firmware:\n\n2.16.1 for mbCONNECT24/mymbCONNECT24\n8.2.0 for mbNET/mbNET.rokey","title":"Remediation"}],"publisher":{"category":"vendor","contact_details":"security-team@mbconnectline.de","name":"MB connect line GmbH","namespace":"https://mbconnectline.com"},"references":[{"category":"external","summary":"CERT@VDE Security Advisories for MB connect line GmbH","url":"https://certvde.com/en/advisories/vendor/mbconnectline/"},{"category":"self","summary":"VDE-2024-042: MB connect line: Multiple products are vulnerable to regreSSHion - HTML","url":"https://certvde.com/en/advisories/VDE-2024-042/"},{"category":"self","summary":"VDE-2024-042: MB connect line: Multiple products are vulnerable to regreSSHion - CSAF","url":"https://mbconnectline.csaf-tp.certvde.com/.well-known/csaf/white/2023/vde-2024-042.json"}],"title":"MB connect line: Multiple products are vulnerable to regreSSHion","tracking":{"aliases":["VDE-2024-042"],"current_release_date":"2023-08-17T12:00:00.000Z","generator":{"date":"2025-06-12T08:19:54.167Z","engine":{"name":"Secvisogram","version":"2.5.27"}},"id":"VDE-2024-042","initial_release_date":"2023-08-17T12:00:00.000Z","revision_history":[{"date":"2023-08-17T12:00:00.000Z","number":"1.0.0","summary":"Initial revision."}],"status":"final","version":"1.0.0"}},"product_tree":{"branches":[{"branches":[{"branches":[{"branches":[{"category":"product_version_range","name":"<2.16.1","product":{"name":"mbCONNECT24 <2.16.1","product_id":"CSAFPID-51001"}},{"category":"product_version","name":"2.16.1","product":{"name":"mbCONNECT24 2.16.1","product_id":"CSAFPID-52001"}}],"category":"product_name","name":"mbCONNECT24"},{"branches":[{"category":"product_version_range","name":"8.0.0<8.2.0","product":{"name":"mbNET 8.0.0<8.2.0","product_id":"CSAFPID-51002"}},{"category":"product_version","name":"8.2.0","product":{"name":"mbNET 8.2.0","product_id":"CSAFPID-52002"}}],"category":"product_name","name":"mbNET"},{"branches":[{"category":"product_version_range","name":"8.0.0<8.2.0","product":{"name":"mbNET.rokey 8.0.0<8.2.0","product_id":"CSAFPID-51003"}},{"category":"product_version","name":"8.2.0","product":{"name":"mbNET.rokey 8.2.0","product_id":"CSAFPID-52003"}}],"category":"product_name","name":"mbNET.rokey"},{"branches":[{"category":"product_version_range","name":"<2.16.1","product":{"name":"mymbCONNECT24 <2.16.1","product_id":"CSAFPID-51004"}},{"category":"product_version","name":"2.16.1","product":{"name":"mymbCONNECT24 2.16.1","product_id":"CSAFPID-52004"}}],"category":"product_name","name":"mymbCONNECT24"}],"category":"product_family","name":"Software"}],"category":"vendor","name":"Red Lion Europe"},{"branches":[{"branches":[{"branches":[{"category":"product_version_range","name":"<2.16.1","product":{"name":"mbCONNECT24 <2.16.1","product_id":"CSAFPID-51005"}},{"category":"product_version","name":"2.16.1","product":{"name":"mbCONNECT24 2.16.1","product_id":"CSAFPID-52005"}}],"category":"product_name","name":"mbCONNECT24"},{"branches":[{"category":"product_version_range","name":"8.0.0<8.2.0","product":{"name":"mbNET 8.0.0<8.2.0","product_id":"CSAFPID-51006"}},{"category":"product_version","name":"8.2.0","product":{"name":"mbNET 8.2.0","product_id":"CSAFPID-52006"}}],"category":"product_name","name":"mbNET"},{"branches":[{"category":"product_version_range","name":"8.0.0<8.2.0","product":{"name":"mbNET.rokey 8.0.0<8.2.0","product_id":"CSAFPID-51007"}},{"category":"product_version","name":"8.2.0","product":{"name":"mbNET.rokey 8.2.0","product_id":"CSAFPID-52007"}}],"category":"product_name","name":"mbNET.rokey"},{"branches":[{"category":"product_version_range","name":"<2.16.1","product":{"name":"mymbCONNECT24 <2.16.1","product_id":"CSAFPID-51008"}},{"category":"product_version","name":"2.16.1","product":{"name":"mymbCONNECT24 2.16.1","product_id":"CSAFPID-52008"}}],"category":"product_name","name":"mymbCONNECT24"}],"category":"product_family","name":"Software"}],"category":"vendor","name":"MB connect line"}],"product_groups":[{"group_id":"CSAFGID-0001","product_ids":["CSAFPID-51001","CSAFPID-51002","CSAFPID-51003","CSAFPID-51004","CSAFPID-51005","CSAFPID-51006","CSAFPID-51007","CSAFPID-51008"],"summary":"Affected products "},{"group_id":"CSAFGID-0002","product_ids":["CSAFPID-52001","CSAFPID-52002","CSAFPID-52003","CSAFPID-52004","CSAFPID-52005","CSAFPID-52006","CSAFPID-52007","CSAFPID-52008"],"summary":"Fixed products"}]},"vulnerabilities":[{"cve":"CVE-2024-6387","cwe":{"id":"CWE-362","name":"Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"},"notes":[{"category":"description","text":"A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.","title":"Vulnerability Description"}],"product_status":{"fixed":["CSAFPID-52001","CSAFPID-52002","CSAFPID-52003","CSAFPID-52004","CSAFPID-52005","CSAFPID-52006","CSAFPID-52007","CSAFPID-52008"],"known_affected":["CSAFPID-51001","CSAFPID-51002","CSAFPID-51003","CSAFPID-51004","CSAFPID-51005","CSAFPID-51006","CSAFPID-51007","CSAFPID-51008"]},"remediations":[{"category":"mitigation","details":"Prevent all access to the sshd daemon listening on port 22.","group_ids":["CSAFGID-0001"]},{"category":"vendor_fix","details":"Update to latest firmware:\n\n2.16.1 for mbCONNECT24/mymbCONNECT24\n8.2.0 for mbNET/mbNET.rokey","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","environmentalScore":8.1,"environmentalSeverity":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":8.1,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-51001","CSAFPID-51002","CSAFPID-51003","CSAFPID-51004","CSAFPID-51005","CSAFPID-51006","CSAFPID-51007","CSAFPID-51008"]}],"title":"CVE-2024-6387"}]}