CVE-2024-6387 - OpenSSH RegreSSHion RCE

RegreSSHion Vulnerability (CVE-2024-6387) On July 1, 2024, a critical signal handler race condition vulnerability was disclosed in OpenSSH servers (sshd) on glibc-based Linux systems. This vulnerability, known as RegreSSHion and tracked as CVE-2024-6387, can result in unauthenticated remote code execution (RCE) with root privileges. This vulnerability has been rated High severity (CVSS 8.1). #### Impacted Versions The vulnerability impacts the following OpenSSH server versions: - OpenSSH versions between 8.5p1 and 9.8p1 - OpenSSH versions earlier than 4.4p1, if they have not been backport-patched against CVE-2006-5051 or patched against CVE-2008-4109 #### Unaffected Versions The SSH features in PAN-OS are not affected by CVE-2024-6387. ### The playbook includes the following tasks: **Collect, Extract and Enrich Indicators** * Collect known indicators from Unit42 blog **Threat Hunting** * Searches vulnerable endpoints using Prisma Cloud and Cortex XDR - XQL queries **Mitigations:** * OpenSSH official CVE-2024-6387 patch * Unit42 recommended mitigations **This playbook should be triggered manually or can be configured as a job.** Please create a new incident and choose the CVE-2024-6387 - OpenSSH RegreSSHion RCE playbook and Rapid Breach Response incident type. Reference: [Threat Brief: CVE-2024-6387 OpenSSH RegreSSHion Vulnerability ](https://unit42.paloaltonetworks.com/threat-brief-cve-2024-6387-openssh/). Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.

CVE-2024-6387 - OpenSSH RegreSSHion RCE · 23 tasks · 4 inputs · 0 outputs

Details

IDCVE-2024-6387 - OpenSSH RegreSSHion RCE
From Version6.10.0
Tasks23

README

RegreSSHion Vulnerability (CVE-2024-6387)

On July 1, 2024, a critical signal handler race condition vulnerability was disclosed in OpenSSH servers (sshd) on glibc-based Linux systems. This vulnerability, known as RegreSSHion and tracked as CVE-2024-6387, can result in unauthenticated remote code execution (RCE) with root privileges. This vulnerability has been rated High severity (CVSS 8.1).

Impacted Versions

The vulnerability impacts the following OpenSSH server versions:

  • OpenSSH versions between 8.5p1 and 9.8p1
  • OpenSSH versions earlier than 4.4p1, if they have not been backport-patched against CVE-2006-5051 or patched against CVE-2008-4109

Unaffected Versions

The SSH features in PAN-OS are not affected by CVE-2024-6387.

The playbook includes the following tasks:

Collect, Extract and Enrich Indicators

  • Collect known indicators from Unit42 blog

Threat Hunting

  • Searches vulnerable endpoints using Prisma Cloud and Cortex XDR - XQL queries

Mitigations:

  • OpenSSH official CVE-2024-6387 patch
  • Unit42 recommended mitigations

This playbook should be triggered manually or can be configured as a job.

Please create a new incident and choose the CVE-2024-6387 - OpenSSH RegreSSHion RCE playbook and Rapid Breach Response incident type.

Reference:

Threat Brief: CVE-2024-6387 OpenSSH RegreSSHion Vulnerability
.

Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • Rapid Breach Response - Set Incident Info

Integrations

This playbook does not use any integrations.

Scripts

  • ParseHTMLIndicators
  • IsIntegrationAvailable
  • PrettyPrint

Commands

  • enrichIndicators
  • send-mail
  • xdr-xql-generic-query
  • extractIndicators
  • createNewIndicator
  • prisma-cloud-compute-ci-scan-results-list

Playbook Inputs


Name Description Default Value Required
PlaybookDescription The playbook description to populate the layout with. RegreSSHion Vulnerability (CVE-2024-6387)

On July 1, 2024, a critical signal handler race condition vulnerability was disclosed in OpenSSH servers (sshd) on glibc-based Linux systems. This vulnerability, known as RegreSSHion and tracked as CVE-2024-6387, can result in unauthenticated remote code execution (RCE) with root privileges. This vulnerability has been rated High severity (CVSS 8.1).

## Impacted Versions

The vulnerability impacts the following OpenSSH server versions:

- OpenSSH versions between 8.5p1 and 9.8p1
- OpenSSH versions earlier than 4.4p1, if they have not been backport-patched against CVE-2006-5051 or patched against CVE-2008-4109

## Unaffected Versions

The SSH features in PAN-OS are not affected by CVE-2024-6387.
Optional
RunXQLHuntingQueries Whether to execute the XQL query. True Optional
ShouldSendMail Whether to notify the SOC by email. False Optional
SOCEmailAddress The email address to notify   Optional

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


CVE-2024-6387 - OpenSSH RegreSSHion RCE

Inputs

  • PlaybookDescription — The playbook description to populate the layout with.
  • RunXQLHuntingQueries — Whether to execute the XQL query.
  • ShouldSendMail — Whether to notify the SOC by email.
  • SOCEmailAddress — The email address to notify

Commands used

createNewIndicator enrichIndicators extractIndicators prisma-cloud-compute-ci-scan-results-list send-mail xdr-xql-generic-query

Flowchart

yes no yes yes yes Start Start Collect Indicators from Unit42 - ParseHTMLIndicators Collect Indicators from U... ParseHTMLIndicators Extract and Tag Indicators Extract and Tag Indicators Create indicators in TIM - createNewIndicator Create indicators in TIM createNewIndicator Extract Indicators - extractIndicators Extract Indicators extractIndicators Collect Indicators Collect Indicators Handle Rapid Breach Response Layout Handle Rapid Breach Respo... Rapid Breach Response - Set Incident Info - Rapid Breach Response - Set Incident Info Rapid Breach Response - S... Rapid Breach Response - Set I... Threat Hunting Threat Hunting Unit42 Managed Threat Hunting Queries Unit42 Managed Threat Hun... Prisma Cloud Prisma Cloud Should run XQL hunting queries? Should run XQL hunting qu... Check if Cortex XDR - XQL Query Engine is Enabled - IsIntegrationAvailable Check if Cortex XDR - XQL... IsIntegrationAvailable Hunt to identify hosts vulnerable to CVE-2024-6387 - xdr-xql-generic-query Hunt to identify hosts vu... xdr-xql-generic-query Were vulnerable endpoints found? Were vulnerable endpoints... Search for vulnerable resources - prisma-cloud-compute-ci-scan-results-list Search for vulnerable res... prisma-cloud-compute-ci-scan-... Mitigation Mitigation Hold for an update regarding the endpoint mitigation Hold for an update regard... Done Done Recommended Mitigations - PrettyPrint Recommended Mitigations PrettyPrint Notify the SOC about the vulnerable endpoints - send-mail Notify the SOC about the ... send-mail Should notify the SOC by email? Should notify the SOC by ... Enrich Indicators - enrichIndicators Enrich Indicators enrichIndicators
id: CVE-2024-6387 - OpenSSH RegreSSHion RCE
version: -1
name: CVE-2024-6387 - OpenSSH RegreSSHion RCE
description: |-
  RegreSSHion Vulnerability (CVE-2024-6387)

  On July 1, 2024, a critical signal handler race condition vulnerability was disclosed in OpenSSH servers (sshd) on glibc-based Linux systems. This vulnerability, known as RegreSSHion and tracked as CVE-2024-6387, can result in unauthenticated remote code execution (RCE) with root privileges. This vulnerability has been rated High severity (CVSS 8.1).

  #### Impacted Versions

  The vulnerability impacts the following OpenSSH server versions:

  - OpenSSH versions between 8.5p1 and 9.8p1
  - OpenSSH versions earlier than 4.4p1, if they have not been backport-patched against CVE-2006-5051 or patched against CVE-2008-4109

  #### Unaffected Versions

  The SSH features in PAN-OS are not affected by CVE-2024-6387.

  ### The playbook includes the following tasks:

  **Collect, Extract and Enrich Indicators**
  * Collect known indicators from Unit42 blog

  **Threat Hunting**
  * Searches vulnerable endpoints using Prisma Cloud and Cortex XDR - XQL queries

  **Mitigations:**
  * OpenSSH official CVE-2024-6387 patch
  * Unit42 recommended mitigations
  
  **This playbook should be triggered manually or can be configured as a job.** 

  Please create a new incident and choose the CVE-2024-6387 - OpenSSH RegreSSHion RCE playbook and Rapid Breach Response incident type.
  
  Reference:
  
  [Threat Brief: CVE-2024-6387 OpenSSH RegreSSHion Vulnerability
  ](https://unit42.paloaltonetworks.com/threat-brief-cve-2024-6387-openssh/).
  
  Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: 94adeb69-7e9a-4a89-8765-b6752c05df1c
    type: start
    task:
      id: 94adeb69-7e9a-4a89-8765-b6752c05df1c
      version: -1
      name: ""
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "5"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": -240
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "1":
    id: "1"
    taskid: 7a39d8d2-ac92-445a-8854-ebc57270e381
    type: regular
    task:
      id: 7a39d8d2-ac92-445a-8854-ebc57270e381
      version: -1
      name: Collect Indicators from Unit42
      description: This script will extract indicators from given HTML and will handle bad top-level domains to avoid false positives caused by file extensions.
      scriptName: ParseHTMLIndicators
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "2"
    scriptarguments:
      url:
        simple: https://unit42.paloaltonetworks.com/threat-brief-cve-2024-6387-openssh/
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 20
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "2":
    id: "2"
    taskid: 06591089-1b00-4ab7-8b90-f11ff525fae2
    type: title
    task:
      id: 06591089-1b00-4ab7-8b90-f11ff525fae2
      version: -1
      name: Extract and Tag Indicators
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "4"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 180
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "3":
    id: "3"
    taskid: b38ed8c9-cd4f-46c1-83f6-0ebf43f5378c
    type: regular
    task:
      id: b38ed8c9-cd4f-46c1-83f6-0ebf43f5378c
      version: -1
      name: Create indicators in TIM
      description: commands.local.cmd.new.indicator
      script: Builtin|||createNewIndicator
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "6"
    scriptarguments:
      tags:
        simple: RegreSSHion, OpenSSH, RCE
      type:
        simple: CVE
      value:
        complex:
          root: ExtractedIndicators
          accessor: CVE
          transformers:
          - operator: uniq
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 640
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "4":
    id: "4"
    taskid: 646abc1c-8377-4cf4-861c-e6d26647af4d
    type: regular
    task:
      id: 646abc1c-8377-4cf4-861c-e6d26647af4d
      version: -1
      name: Extract Indicators
      description: commands.local.cmd.extract.indicators
      script: Builtin|||extractIndicators
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "30"
    scriptarguments:
      text:
        simple: ${http.parsedBlog.indicators}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 315
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "5":
    id: "5"
    taskid: c4f179ef-d905-46f5-8743-3f39170e36cf
    type: title
    task:
      id: c4f179ef-d905-46f5-8743-3f39170e36cf
      version: -1
      name: Collect Indicators
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "1"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": -110
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "6":
    id: "6"
    taskid: 8fd54c1e-180d-45de-8def-93fc184bbf6c
    type: title
    task:
      id: 8fd54c1e-180d-45de-8def-93fc184bbf6c
      version: -1
      name: Handle Rapid Breach Response Layout
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "7"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 810
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "7":
    id: "7"
    taskid: d89e9319-fe26-4a4f-89e5-4a42203a3c15
    type: playbook
    task:
      id: d89e9319-fe26-4a4f-89e5-4a42203a3c15
      version: -1
      name: Rapid Breach Response - Set Incident Info
      description: This playbook is responsible for setting up the Rapid Breach Response Incident Info tab in the layout.
      playbookName: Rapid Breach Response - Set Incident Info
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "8"
    scriptarguments:
      SourceOfIndicators:
        simple: ${http.parsedBlog.sourceLink}
      countTotalIndicators:
        complex:
          root: ExtractedIndicators
          accessor: CVE
          transformers:
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.Domain
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.IP
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.URL
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
          - operator: uniq
          - operator: count
      playbookDescription:
        simple: ${inputs.PlaybookDescription}
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 450,
          "y": 940
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "8":
    id: "8"
    taskid: ef31c540-d451-4ea9-8d4a-a852e9783e45
    type: title
    task:
      id: ef31c540-d451-4ea9-8d4a-a852e9783e45
      version: -1
      name: Threat Hunting
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "9"
      - "11"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 1100
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "9":
    id: "9"
    taskid: 878e0ae1-e27b-48d1-8424-b64258a88ccd
    type: title
    task:
      id: 878e0ae1-e27b-48d1-8424-b64258a88ccd
      version: -1
      name: Unit42 Managed Threat Hunting Queries
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "12"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 200,
          "y": 1250
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "11":
    id: "11"
    taskid: 8773b606-9c32-4742-845e-bf425534ff68
    type: title
    task:
      id: 8773b606-9c32-4742-845e-bf425534ff68
      version: -1
      name: Prisma Cloud
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "17"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 690,
          "y": 1250
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "12":
    id: "12"
    taskid: 6bb9d8a2-00c1-4380-87c9-e46aad6c1610
    type: condition
    task:
      id: 6bb9d8a2-00c1-4380-87c9-e46aad6c1610
      version: -1
      name: Should run XQL hunting queries?
      description: Whether to run the XQL hunting queries.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "15"
      "yes":
      - "13"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              simple: inputs.RunXQLHuntingQueries
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 200,
          "y": 1390
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "13":
    id: "13"
    taskid: 475304b6-8672-4e31-8f85-80a0c142b107
    type: condition
    task:
      id: 475304b6-8672-4e31-8f85-80a0c142b107
      version: -1
      name: Check if Cortex XDR - XQL Query Engine is Enabled
      description: Returns 'yes' if integration brand is available. Otherwise returns 'no'.
      scriptName: IsIntegrationAvailable
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      "no":
      - "15"
      "yes":
      - "14"
    scriptarguments:
      brandname:
        simple: Cortex XDR - XQL Query Engine
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 10,
          "y": 1560
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "14":
    id: "14"
    taskid: dd7a29c0-0024-4d25-83dd-90629841e2d8
    type: regular
    task:
      id: dd7a29c0-0024-4d25-83dd-90629841e2d8
      version: -1
      name: Hunt to identify hosts vulnerable to CVE-2024-6387
      description: |-
        Execute an XQL query and retrieve results of an executed XQL query API. The command will be executed every 10 seconds until results are retrieved or until a timeout error is raised.
        When more than 1000 results are retrieved, the command will return a compressed gzipped JSON format file,
        unless the argument 'parse_result_file_to_context' is set to true and then the results will be extracted to the context.
      script: '|||xdr-xql-generic-query'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "15"
    scriptarguments:
      ignore-outputs:
        simple: "false"
      parse_result_file_to_context:
        simple: "true"
      query:
        simple: "preset = host_inventory_applications\n \n| filter endpoint_type = ENUM.AGENT_TYPE_SERVER\n \n| filter lowercase(application_name) ~= \"openssh(-server)?\"\n \n| alter product_major_version = to_number(arrayindex(split(raw_version, \".\"), 0)),\n \nproduct_minor_version_stage_1 = arrayindex(split(raw_version, \".\"), 1),\n \nproduct_rev = to_number(arrayindex(split(raw_version, \"p\"), 1))\n \n| alter product_minor_version = to_number(arrayindex(split(product_minor_version_stage_1, \"p\"), 0))\n \n// (name:\"openssh\" and version<4.4) or (name:\"openssh\" and version<9.8 and version>=8.5)\n \n| filter product_major_version < 4 or (product_major_version = 4 and product_minor_version < 4) or (product_major_version = 8 and product_minor_version >= 5) or (product_major_version = 9 and product_minor_version < 8)\n \n| fields endpoint_name, application_name, raw_version, product_major_version, product_minor_version, product_rev\n \n| dedup endpoint_name"
      query_name:
        simple: Hunt_CVE_-_2024_-_6387_Vulnerable_Endpoints
      time_frame:
        simple: 7 days
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -180,
          "y": 1740
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "15":
    id: "15"
    taskid: ac1b6020-ac56-402d-8b1e-87cf2cf78e3a
    type: condition
    task:
      id: ac1b6020-ac56-402d-8b1e-87cf2cf78e3a
      version: -1
      name: Were vulnerable endpoints found?
      description: Checks if vulnerable endpoints found in the Threat Hunting phase.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "26"
      "yes":
      - "29"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              complex:
                root: PaloAltoNetworksXQL.GenericQuery.results
                accessor: endpoint_name
                transformers:
                - operator: append
                  args:
                    item:
                      value:
                        simple: PrismaCloudCompute.CIScan.entityInfo.hostname
                      iscontext: true
                - operator: append
                  args:
                    item:
                      value:
                        simple: Expanse.Issue.assets.id
                      iscontext: true
            iscontext: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 1910
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "17":
    id: "17"
    taskid: 23f98158-0f08-46a6-888f-27577dc36a5b
    type: regular
    task:
      id: 23f98158-0f08-46a6-888f-27577dc36a5b
      version: -1
      name: Search for vulnerable resources
      description: Retrieves all scan reports for images scanned by the Jenkins plugin or twistcli. Maps to Monitor > Vulnerabilities > Images > CI in the Console UI. The default will retrieve only the passed scans.
      script: '|||prisma-cloud-compute-ci-scan-results-list'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "15"
    scriptarguments:
      all_results:
        simple: "true"
      search:
        simple: vulnerability where asset.type = 'all' AND cve.id = 'CVE-2024-6387'
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 690,
          "y": 1390
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "20":
    id: "20"
    taskid: 363fd235-f892-4edb-8666-b357dff8438c
    type: title
    task:
      id: 363fd235-f892-4edb-8666-b357dff8438c
      version: -1
      name: Mitigation
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "27"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 2430
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "23":
    id: "23"
    taskid: 1ef81cb4-1c73-4b84-8cc2-fe5480c470e8
    type: collection
    task:
      id: 1ef81cb4-1c73-4b84-8cc2-fe5480c470e8
      version: -1
      name: Hold for an update regarding the endpoint mitigation
      description: commands.local.cmd.todo.add
      type: collection
      iscommand: false
      brand: Builtin
    nexttasks:
      '#none#':
      - "26"
    scriptarguments:
      description:
        simple: "The following endpoints have are potentially vulnerable to CVE-2024-6387:\n\nXQL Threat Hunting\n${PaloAltoNetworksXQL.GenericQuery.results.endpoint_name}\n\nPrisma Cloud Compute\n${PrismaCloudCompute.CIScan.entityInfo.hostname}\n\nCortex Xpanse\n${Expanse.Issue.assets.id}\n\nUnit42 recommended mitigations for CVE-2024-6387 are:\n\n1. Update to OpenSSH 9.8p1 or later\nReference: [OpenSSH 9.8](https://www.openssh.com/txt/release-9.8)\n\n2. Harden SSH Configuration\n- LoginGraceTime: Reduce the LoginGraceTime value to minimize the window during which an attacker can attempt to exploit the SSH service. \n    - Open /etc/ssh/sshd_config as root\n    - Add or modify the LoginGraceTime parameter:\n    LoginGraceTime 0\n    - Save the file\n    - Restart the sshd service"
      tags:
        simple: CVE-2024-6387, OpenSSH, RegreSSHion
      title:
        simple: Mitigate Vulnerable Endpoints
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 2730
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    message:
      to:
      subject:
      body:
      methods: []
      format: ""
      bcc:
      cc:
      timings:
        retriescount: 2
        retriesinterval: 360
        completeafterreplies: 1
        completeafterv2: true
        completeaftersla: false
    form:
      questions:
      - id: "0"
        label: ""
        labelarg:
          simple: Which endpoints have been mitigated?
        required: false
        gridcolumns: []
        defaultrows: []
        type: multiSelect
        options: []
        optionsarg:
        - complex:
            root: PrismaCloudCompute.CIScan.entityInfo
            accessor: hostname
            transformers:
            - operator: append
              args:
                item:
                  value:
                    simple: PaloAltoNetworksXQL.GenericQuery.results.endpoint_name
                  iscontext: true
        - {}
        fieldassociated: ""
        placeholder: ""
        tooltip: ""
        readonly: false
      title: Please select mitigated endpoints
      description: ""
      sender: Your SOC team
      expired: false
      totalanswers: 0
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "26":
    id: "26"
    taskid: f4877f7c-e71f-43ae-8162-ad2c13e1fbd1
    type: title
    task:
      id: f4877f7c-e71f-43ae-8162-ad2c13e1fbd1
      version: -1
      name: Done
      type: title
      iscommand: false
      brand: ""
      description: ''
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 2890
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "27":
    id: "27"
    taskid: bbbcc8f0-fed8-40ab-8517-d5eb2aafb994
    type: regular
    task:
      id: bbbcc8f0-fed8-40ab-8517-d5eb2aafb994
      version: -1
      name: Recommended Mitigations
      description: |-
        Pretty-print data using Python's pprint library.  This is useful for seeing the structure of incident and context data.  Here's how to use it:

        !PrettyPrint value=${incident}
      scriptName: PrettyPrint
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "23"
    scriptarguments:
      value:
        simple: |-
          The Unit42 Research team recommends these mitigations:

          1. Upgrade OpenSSH to a patched version 9.8p1 or later.
          2. Harden your OpenSSH LoginGraceTime configuration
              - Open /etc/ssh/sshd_config as root
              - Add or modify the LoginGraceTime parameter as follows:
                  LoginGraceTime 0
              - Save the file
              - Restart the sshd service
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 2570
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "28":
    id: "28"
    taskid: c77a3225-393a-4519-8eec-77d11464b604
    type: regular
    task:
      id: c77a3225-393a-4519-8eec-77d11464b604
      version: -1
      name: Notify the SOC about the vulnerable endpoints
      description: commands.server.mail.sendmail
      script: '|||send-mail'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "20"
    scriptarguments:
      body:
        simple: |-
          Dear SOC,

          The CVE-2024-6387 - OpenSSH RegreSSHion RCE playbook found potentially vulnerable endpoints:

          Prisma Cloud
          ${PrismaCloudCompute.CIScan.entityInfo.hostname}

          Managed Threat Hunting Queries
          ${PaloAltoNetworksXQL.GenericQuery.results.endpoint_name}

          Please follow the steps described in the playbook to mitigate the threat.

          Best regards,
          Cortex XSOAR
      subject:
        simple: Cortex XSOAR - Incident ${incident.id} - CVE-2024-6387 Vulnerable Endpoints
      to:
        simple: ${inputs.SOCEmailAddress}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 2270
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "29":
    id: "29"
    taskid: 551deed2-69b7-491a-8eb6-e4a06d4b0dcd
    type: condition
    task:
      id: 551deed2-69b7-491a-8eb6-e4a06d4b0dcd
      version: -1
      name: Should notify the SOC by email?
      description: Whether to notify the SOC about the affected assets by email.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "20"
      "yes":
      - "28"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              simple: inputs.ShouldSendMail
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 2090
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "30":
    id: "30"
    taskid: 1ae47a6a-03c1-4664-83c7-b0133bc6c218
    type: regular
    task:
      id: 1ae47a6a-03c1-4664-83c7-b0133bc6c218
      version: -1
      name: Enrich Indicators
      description: commands.local.cmd.enrich.indicators
      script: Builtin|||enrichIndicators
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "3"
    scriptarguments:
      indicatorsValues:
        complex:
          root: ExtractedIndicators
          accessor: CVE
          transformers:
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.Domain
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.IP
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.URL
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 450,
          "y": 480
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
view: |-
  {
    "linkLabelsPosition": {
      "12_13_yes": 0.25,
      "12_15_#default#": 0.27,
      "13_14_yes": 0.39,
      "13_15_no": 0.28,
      "15_26_#default#": 0.32,
      "15_29_yes": 0.4,
      "29_28_yes": 0.4
    },
    "paper": {
      "dimensions": {
        "height": 3195,
        "width": 1250,
        "x": -180,
        "y": -240
      }
    }
  }
inputs:
- key: PlaybookDescription
  value:
    simple: |-
      RegreSSHion Vulnerability (CVE-2024-6387)

      On July 1, 2024, a critical signal handler race condition vulnerability was disclosed in OpenSSH servers (sshd) on glibc-based Linux systems. This vulnerability, known as RegreSSHion and tracked as CVE-2024-6387, can result in unauthenticated remote code execution (RCE) with root privileges. This vulnerability has been rated High severity (CVSS 8.1).

      ## Impacted Versions

      The vulnerability impacts the following OpenSSH server versions:

      - OpenSSH versions between 8.5p1 and 9.8p1
      - OpenSSH versions earlier than 4.4p1, if they have not been backport-patched against CVE-2006-5051 or patched against CVE-2008-4109

      ## Unaffected Versions

      The SSH features in PAN-OS are not affected by CVE-2024-6387.
  required: false
  description: The playbook description to populate the layout with.
  playbookInputQuery:
- key: RunXQLHuntingQueries
  value:
    simple: "True"
  required: false
  description: Whether to execute the XQL query.
  playbookInputQuery:
- key: ShouldSendMail
  value:
    simple: "False"
  required: false
  description: Whether to notify the SOC by email.
  playbookInputQuery:
- key: SOCEmailAddress
  value: {}
  required: false
  description: The email address to notify
  playbookInputQuery:
inputSections:
- inputs:
  - PlaybookDescription
  - RunXQLHuntingQueries
  - ShouldSendMail
  - SOCEmailAddress
  name: General (Inputs group)
  description: Generic group for inputs
outputSections:
- outputs: []
  name: General (Outputs group)
  description: Generic group for outputs
outputs: []
tests:
- No tests (auto formatted)
fromversion: 6.10.0