What happened
Multi-target OpenSSH version checker script for CVE-2024-6387 using nmap banner scanning.
Affected versions
Red Hat Enterprise Linux 9: 8.5p1 through 9.7p1 (custom); before * (custom); V3.1.5 through before * (custom); before V1.0 HF1 (custom); before V3.2 SP2 (custom); before V6.24 (custom) Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 52269OpenSSH server (sshd) 9.8p1 - Race ConditionMilad karimi2025-04-22VerifiedSploitusMulti-target OpenSSH version checker script for CVE-2024-6387 using nmap banner scanning.KitPloit2026-09-02T13:01:51Candidatekitploit.comMulti-target OpenSSH version checker script for CVE-2024-6387 using nmap banner scanning.ru2026-09-02T13:01:51CandidateSploitusRace condition in OpenSSH sshd allowing unauthorised remote attacker to execute code.KitPloit2026-09-01T13:59:43Candidatekitploit.comRace condition in OpenSSH sshd allowing unauthorised remote attacker to execute code.ru2026-09-01T13:59:43CandidateSploitusExploit for CVE-2024-6387. CVSS 8.1.Sploitus index2026-09-08T01:20:02+00:00Candidatesantandersecurityresearch.github.ioNVD reference2024-07-01Verifiedwww.qualys.comNVD reference2024-07-01Verifiedwww.openwall.comNVD reference2024-07-01Verifiedwww.openwall.comNVD reference2024-07-01Verifiedwww.openwall.comNVD reference2024-07-01Verifiedwww.openwall.comNVD reference2024-07-01Verifiedwww.openwall.comNVD reference2024-07-01Verifiedwww.vicarius.ioNVD reference2024-07-01VerifiedPoC-in-GitHub · 7etsuo/cve-2024-6387-poca signal handler race condition in OpenSSH's server (sshd)★ 17etsuo2024-07-01CandidatePoC-in-GitHub · zgzhang/cve-2024-6387-poca signal handler race condition in OpenSSH's server (sshd)★ 497zgzhang2024-07-01CandidatePoC-in-GitHub · acrono/cve-2024-6387-poc32-bit PoC for CVE-2024-6387 — mirror of the original 7etsuo/cve-2024-6387-poc★ 378acrono2024-07-01CandidatePoC-in-GitHub · lflare/cve-2024-6387-pocMIRROR of the original 32-bit PoC for CVE-2024-6387 "regreSSHion" by 7etsuo/cve-2024-6387-poc★ 129lflare2024-07-01CandidatePoC-in-GitHub · getdrive/CVE-2024-6387-PoCPoC RCE in OpenSSH★ 25getdrive2024-07-01CandidatePoC-in-GitHub · FerasAlrimali/CVE-2024-6387-POCSSHd cve-2024-6387-poc★ 0FerasAlrimali2024-07-01CandidatePoC-in-GitHub · passwa11/cve-2024-6387-poc★ 1passwa112024-07-01CandidatePoC-in-GitHub · jack0we/CVE-2024-6387★ 0jack0we2024-07-01CandidatePoC-in-GitHub · xaitax/CVE-2024-6387_CheckCVE-2024-6387_Check is a lightweight, efficient tool designed to identify servers running vulnerable versions of OpenSSH★ 528xaitax2024-07-01CandidatePoC-in-GitHub · bigb0x/CVE-2024-6387Bulk Scanning Tool for OpenSSH CVE-2024-6387, CVE-2006-5051 , CVE-2008-4109 and others.★ 35bigb0x2024-07-01CandidatePoC-in-GitHub · wiggels/regresshion-checkCLI Tool to Check SSH Servers for Vulnerability to CVE-2024-6387★ 6wiggels2024-07-01CandidatePoC-in-GitHub · P4x1s/CVE-2024-6387SSH RCE PoC CVE-2024-6387★ 10P4x1s2024-07-02CandidatePoC-in-GitHub · betancour/OpenSSH-Vulnerability-testOpenSSH CVE-2024-6387 Vulnerability Checker★ 2betancour2024-07-02CandidatePoC-in-GitHub · muyuanlove/CVE-2024-6387fixshell★ 2muyuanlove2024-07-02CandidatePoC-in-GitHub · TAM-K592/CVE-2024-6387Recently, the OpenSSH maintainers released security updates to fix a critical vulnerability that could lead to unauthenticated remote code execution (RCE) with root privileges. This vulnerability, identified as CVE-2024-6387, resides in the OpenSSH server component (sshd), which is designed to listen for connections from client applications.★ 14TAM-K5922024-07-02CandidatePoC-in-GitHub · teamos-hub/regreSSHionThis is a POC I wrote for CVE-2024-6387★ 1teamos-hub2024-07-02CandidatePoC-in-GitHub · ahlfors/CVE-2024-6387★ 2ahlfors2024-07-02CandidatePoC-in-GitHub · Mufti22/CVE-2024-6387-checkher★ 0Mufti222024-07-02CandidatePoC-in-GitHub · thegenetic/CVE-2024-6387-exploitCVE-2024-6387 exploit★ 13thegenetic2024-07-02CandidatePoC-in-GitHub · R4Tw1z/CVE-2024-6387This script, created by R4Tw1z, is designed to scan IP addresses to check if they are running a potentially vulnerable version of OpenSSH. The tool leverages multi-threading to optimize scanning performance and handle multiple IP addresses concurrently.★ 1R4Tw1z2024-07-02CandidatePoC-in-GitHub · d0rb/CVE-2024-6387This Python script exploits a remote code execution vulnerability (CVE-2024-6387) in OpenSSH.★ 52d0rb2024-07-02CandidatePoC-in-GitHub · CiderAndWhisky/regression-scannerUsed to detect ssh servers vulnerable to CVE-2024-6387. Shameless robbery from https://github.com/bigb0x/CVE-2024-6387 using ChatGPT to translate the code to PHP.★ 0CiderAndWhisky2024-07-02CandidatePoC-in-GitHub · shamo0/CVE-2024-6387_PoCScript for checking CVE-2024-6387 (regreSSHion)★ 1shamo02024-07-02CandidatePoC-in-GitHub · paradessia/CVE-2024-6387-nmapCVE-2024-6387-nmap★ 4paradessia2024-07-02CandidatePoC-in-GitHub · PrincipalAnthony/CVE-2024-6387-Updated-x64bitPrivate x64 RCE exploit for CVE-2024-6387 [02.07.2024] from exploit.in★ 3PrincipalAnthony2024-07-02CandidatePoC-in-GitHub · daniel-odrinski/CVE-2024-6387-Mitigation-Ansible-PlaybookAn Ansible Playbook to mitigate the risk of RCE (CVE-2024-6387) until platforms update OpenSSH to a non-vulnerable version.★ 0daniel-odrinski2024-07-02CandidatePoC-in-GitHub · rumochnaya/openssh-cve-2024-6387.shopenssh-cve-2024-6387.sh★ 1rumochnaya2024-07-02CandidatePoC-in-GitHub · zenzue/CVE-2024-6387-MitigationMitigation Guide for CVE-2024-6387 in OpenSSH★ 0zenzue2024-07-02CandidatePoC-in-GitHub · devarshishimpi/CVE-2024-6387-CheckFast, efficient, and reliable detection for the regreSSHion exploit. Scan multiple targets in seconds with zero dependencies.★ 14devarshishimpi2024-07-02CandidatePoC-in-GitHub · hssmo/cve-2024-6387_AImadecve-2024-6387_AImade★ 0hssmo2024-07-02CandidatePoC-in-GitHub · ACHUX21/checker-CVE-2024-6387Python scanner that checks hosts for the OpenSSH regreSSHion vulnerability (CVE-2024-6387)★ 2ACHUX212024-07-02CandidatePoC-in-GitHub · AiGptCode/ssh_exploiter_CVE-2024-6387CVE-2024-6387 with auto ip scanner and auto expliot★ 10AiGptCode2024-07-02CandidatePoC-in-GitHub · xristos8574/regreSSHion-nmap-scannerA bash script for nmap to scan for vulnerable machines in regards to the latest CVE-2024-6387★ 1xristos85742024-07-02CandidatePoC-in-GitHub · particle99/CVE-2024-6387-POCfork for proof of concept of the regresshion vulnerability★ 0particle992024-07-02CandidatePoC-in-GitHub · xonoxitron/regreSSHionCVE-2024-6387 (regreSSHion) Exploit (PoC), a vulnerability in OpenSSH's server (sshd) on glibc-based Linux systems.★ 69xonoxitron2024-07-02CandidatePoC-in-GitHub · no-one-sec/CVE-2024-6387开箱即用的AK47★ 0no-one-sec2024-07-02CandidatePoC-in-GitHub · dawnl3ss/CVE-2024-6387★ 0dawnl3ss2024-07-02CandidatePoC-in-GitHub · MrR0b0t19/CVE-2024-6387-Exploit-POC★ 4MrR0b0t192024-07-02CandidatePoC-in-GitHub · th3gokul/CVE-2024-6387CVE-2024-6387 : Vulnerability Detection tool for regreSSHion Remote Unauthenticated Code Execution in OpenSSH Server★ 4th3gokul2024-07-02CandidatePoC-in-GitHub · n1cks0n/Test_CVE-2024-6387Test_CVE-2024-6387 is a lightweight, efficient tool designed to identify servers running vulnerable versions of OpenSSH★ 1n1cks0n2024-07-02CandidatePoC-in-GitHub · l0n3m4n/CVE-2024-6387PoC - Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (Scanner and Exploit)★ 113l0n3m4n2024-07-02CandidatePoC-in-GitHub · RickGeex/CVE-2024-6387-CheckerCVE-2024-6387-Check is a streamlined and efficient tool created to detect servers operating on vulnerable versions of OpenSSH.★ 3RickGeex2024-07-02CandidatePoC-in-GitHub · xonoxitron/regreSSHion-checkerQuickly identifies servers vulnerable to OpenSSH 'regreSSHion' (CVE-2024-6387).★ 10xonoxitron2024-07-02CandidatePoC-in-GitHub · BrandonLynch2402/cve-2024-6387-nuclei-template★ 3BrandonLynch24022024-07-02CandidatePoC-in-GitHub · edsonjt81/CVE-2024-6387_Check★ 0edsonjt812024-07-02CandidatePoC-in-GitHub · grupooruss/CVE-2024-6387regreSSHion vulnerability in OpenSSH CVE-2024-6387 Testing Script★ 2grupooruss2024-07-02CandidatePoC-in-GitHub · CognisysGroup/CVE-2024-6387-Checker★ 0CognisysGroup2024-07-02CandidatePoC-in-GitHub · sxlmnwb/CVE-2024-6387Targeting a signal handler race condition in OpenSSH's server (sshd) on glibc-based Linux systems.★ 21sxlmnwb2024-07-03CandidatePoC-in-GitHub · Symbolexe/CVE-2024-6387SSH Exploit for CVE-2024-6387 : RCE in OpenSSH's server, on glibc-based Linux systems★ 3Symbolexe2024-07-03CandidatePoC-in-GitHub · harshinsecurity/sentinelsshSentinelSSH is an advanced, high-performance SSH vulnerability scanner written in Go. It's specifically designed to detect the CVE-2024-6387 vulnerability in OpenSSH servers across various network environments.★ 4harshinsecurity2024-07-03CandidatePoC-in-GitHub · t3rry327/cve-2024-6387-poc★ 0t3rry3272024-07-03CandidatePoC-in-GitHub · jocker2410/CVE-2024-6387_poc★ 0jocker24102024-07-03CandidatePoC-in-GitHub · turbobit/CVE-2024-6387-OpenSSH-Vulnerability-CheckerWelcome to the CVE-2024-6387 OpenSSH Vulnerability Checker repository! This project offers multiple scripts to check the installed version of OpenSSH on your system and determine if it is vulnerable to CVE-2024-6387. It supports various environments, including Ubuntu, Mac, and Windows.★ 1turbobit2024-07-04CandidatePoC-in-GitHub · sms2056/CVE-2024-6387★ 0sms20562024-07-04CandidatePoC-in-GitHub · invaderslabs/regreSSHion-CVE-2024-6387-Provides instructions for using the script to check if your OpenSSH installation is vulnerable to CVE-2024-6387★ 0invaderslabs2024-07-04CandidatePoC-in-GitHub · lala-amber/CVE-2024-6387★ 4lala-amber2024-07-04CandidatePoC-in-GitHub · 4lxprime/regreSSHiverewrited SSH Exploit for CVE-2024-6387 (regreSSHion)★ 04lxprime2024-07-04CandidatePoC-in-GitHub · sardine-web/CVE-2024-6387_CheckA security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead to sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.★ 0sardine-web2024-07-04CandidatePoC-in-GitHub · 0x4D31/cve-2024-6387_hasshHASSH fingerprints for identifying OpenSSH servers potentially vulnerable to CVE-2024-6387 (regreSSHion).★ 100x4D312024-07-05CandidatePoC-in-GitHub · sardine-web/CVE-2024-6387-templateQuick regreSSHion checker (based on software version) for nuclei CVE-2024-6387★ 1sardine-web2024-07-05CandidatePoC-in-GitHub · imv7/CVE-2024-6387★ 0imv72024-07-05CandidatePoC-in-GitHub · azurejoga/CVE-2024-6387-how-to-fixVulnerability remediation and mitigationCVE-2024-6387★ 5azurejoga2024-07-05CandidatePoC-in-GitHub · Karmakstylez/CVE-2024-6387Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (CVE-2024-6387)★ 196Karmakstylez2024-07-08CandidatePoC-in-GitHub · vkaushik-chef/regreSSHionChef Inspec profile for checking regreSSHion vulnerability CVE-2024-6387★ 0vkaushik-chef2024-07-08CandidatePoC-in-GitHub · dgourillon/mitigate-CVE-2024-6387★ 0dgourillon2024-07-09CandidatePoC-in-GitHub · mrmtwoj/CVE-2024-6387regreSSHion is a security tool designed to test for vulnerabilities related to CVE-2024-6387, specifically focusing on SSH and remote access exploitation.★ 0mrmtwoj2024-07-09CandidatePoC-in-GitHub · filipi86/CVE-2024-6387-Vulnerability-CheckerThis Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports. The script can also read addresses from a file.★ 102filipi862024-07-09CandidatePoC-in-GitHub · kubota/CVE-2024-6387-Vulnerability-CheckerThis Rust Code is designed to check SSH servers for the CVE-2024-6387 vulnerability★ 0kubota2024-07-09CandidatePoC-in-GitHub · DimaMend/cve-2024-6387-poc★ 0DimaMend2024-07-10CandidatePoC-in-GitHub · redux-sibi-jose/mitigate_sshOpenSSH vulnerability CVE-2024-6387★ 1redux-sibi-jose2024-07-11CandidatePoC-in-GitHub · dream434/CVE-2024-6387OpenSSH a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-6387. Cette vulnérabilité permet à un attaquant non authentifié d'exécuter du code arbitraire★ 0dream4342024-07-14CandidatePoC-in-GitHub · Ap0dexMe0/CVE-2024-6387OpenSSH RCE Massive Vulnerable Scanner★ 3Ap0dexMe02024-07-15CandidatePoC-in-GitHub · prelearn-code/CVE-2024-6387★ 2prelearn-code2024-07-25CandidatePoC-in-GitHub · l-urk/CVE-2024-6387Proof of concept python script for regreSSHion exploit.★ 12l-urk2024-07-30CandidatePoC-in-GitHub · alex14324/ssh_poc2024An exploit for CVE-2024-6387, targeting a signal handler race condition in OpenSSH's server★ 1alex143242024-07-31CandidatePoC-in-GitHub · X-Projetion/CVE-2023-4596-OpenSSH-Multi-CheckerCVE-2024-6387-checker is a tool or script designed to detect the security vulnerability known as CVE-2024-6387 OpenSSH. CVE-2024-6387 OpenSSH is an entry in the Common Vulnerabilities and Exposures (CVE) that documents security weaknesses discovered in certain software or systems.★ 1X-Projetion2024-08-06CandidatePoC-in-GitHub · s1d6point7bugcrowd/CVE-2024-6387-Race-Condition-in-Signal-Handling-for-OpenSSH★ 0s1d6point7bugcrowd2024-08-19CandidatePoC-in-GitHub · almogopp/OpenSSH-CVE-2024-6387-FixA Bash script to mitigate the CVE-2024-6387 vulnerability in OpenSSH by providing an option to upgrade to a secure version or apply a temporary workaround. This repository helps secure systems against potential remote code execution risks associated with affected OpenSSH versions.★ 0almogopp2024-08-20CandidatePoC-in-GitHub · HadesNull123/CVE-2024-6387_CheckRCE OpenSSH CVE-2024-6387 Check and Exploit★ 0HadesNull1232024-08-26CandidatePoC-in-GitHub · identity-threat-labs/CVE-2024-6387-Vulnerability-CheckerThis Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports. The script can also read addresses from a file.★ 2identity-threat-labs2024-08-28CandidatePoC-in-GitHub · identity-threat-labs/Article-RegreSSHion-CVE-2024-6387In an era where digital security is crucial, a new vulnerability in OpenSSH, identified as CVE-2024-6387, has drawn the attention of system administrators and security professionals worldwide. Named "regreSSHion," this severe security flaw allows remote code execution (RCE) and could significant threat to the integrity of vulnerable systems.★ 1identity-threat-labs2024-08-29CandidatePoC-in-GitHub · anhvutuan/CVE-2024-6387-poc-1CVE-2024-6387, also known as RegreSSHion, is a high-severity vulnerability found in OpenSSH servers (sshd) running on glibc-based Linux systems. It is a regression of a previously fixed vulnerability (CVE-2006-5051), which means the issue was reintroduced in newer versions of OpenSSH.★ 2anhvutuan2024-10-22CandidatePoC-in-GitHub · YassDEV221608/CVE-2024-6387★ 0YassDEV2216082024-11-24CandidatePoC-in-GitHub · awusan125/test_for6387test code for cve-2024-6387★ 3awusan1252024-12-19CandidatePoC-in-GitHub · YassDEV221608/CVE-2024-6387_PoC★ 17YassDEV2216082025-01-04CandidatePoC-in-GitHub · kinu404/CVE-2024-6387This is an altered PoC for d0rb/CVE-2024-6387. This takes glibc addresses and trys to exploit the CVE through them.★ 4kinu4042025-01-20CandidatePoC-in-GitHub · xiw1ll/CVE-2024-6387_CheckerNuclei template to detect CVE-2024-6387. All latest patched versions are excluded.★ 1xiw1ll2025-07-23CandidatePoC-in-GitHub · moften/regreSSHion-CVE-2024-6387CVE-2024-6387★ 0moften2025-09-08CandidatePoC-in-GitHub · OHHDamnBRO/NoregresshCVE-2024-6387 and more Checker and Exploiter - Reverse/Bind-Shell Support. education only★ 2OHHDamnBRO2025-09-26CandidatePoC-in-GitHub · Doux-x/CVE-2024-6387-analysisCVE-2024-6387 OpenSSH 信号竞争漏洞(regreSSHion)分析报告及检测脚本★ 0Doux-x2026-03-30CandidatePoC-in-GitHub · kaleth4/CVE-2024-6387★ 0kaleth42026-03-31CandidatePoC-in-GitHub · oseasfr/Scanner_CVE_OpenSSHScanner para identificação de servidores com softwares SSH possivelmente vulnerável às CVEs CVE-2024-6387 e CVE-2023-48795.★ 1oseasfr2026-05-21CandidatePoC-in-GitHub · vuducmanhno100-cloud/CVE-2024-6387CVE-2024-6387 POC (Currently being edited)★ 0vuducmanhno100-cloud2026-05-22CandidatePoC-in-GitHub · m0n3ef/regreSSHion-CheckerA lightweight, fast tool to scan and detect the "regreSSHion" OpenSSH remote code execution vulnerability (CVE-2024-6387).★ 3m0n3ef2026-07-15CandidatePoC-in-GitHub · al7araziruby-jpg/CVE-2024-6387-OpenSSH-AnalysisSecurity analysis and report of CVE-2024-6387 OpenSSH vulnerability, including vulnerability details, CVSS evaluation, and mitigation recommendations.★ 0al7araziruby-jpg2026-07-23CandidatePoC-in-GitHub · hasan8babiker/CVE-2024-6387★ 0hasan8babiker2026-08-06CandidateSource timeline
Discovered through Exploit-DBView source ↗
CVE record published by NVDView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.