2024-07-08
Cisco Provides List of Their Products Containing RegreSSHion Vulnerability
Cisco has published a list of their products they say contain the RegreSSHion vulnerability. The list includes 42 products confirmed to be vulnerable; an additional 51 products are still being investigated for the vulnerability. The remote code execution vulnerability, which was discovered by Qualys researchers, affects the OpenSSH server (sshd) in glibc-based Linux systems.
Editor's Note
In case you missed it, RegreSSHion affects most currently in use versions of ssh. While not easy to exploit, you should look in particular at devices like routers and switches if updates are available.

Johannes Ullrich
The list identifies both affected and _NOT_ affected products. Read carefully. Cisco has published Snort rules to detect exploitation and recommends restricting SSH access to trusted hosts only. Other workarounds will be in the product specific bug references. Keep an eye on their Vulnerable Products list for information about when fixes are available. Due to the lack of immediate fixes, you want to get on those restrictions to the SSH service.

Lee Neely
Cisco is a massive company with multiple product lines built both organically and through acquisition. One of their primary management protocols outside of HTTPS will be SSH. Unfortunately for them, this bug is going to be a hard one for all those business units to locate since it's a specific set of builds that are affected and not all builds. Expect them to take a bit to figure out what's affected and what's not, and based on their EoL/EoS cycles, you'll see several builds back.

Moses Frost
Lists of vulnerable products from suppliers are useful only if one has a list of all products one is using.
