Is EFT affected by the CVE-2024-6387 vulnerability?


THE INFORMATION IN THIS ARTICLE APPLIES TO:

  • EFT all versions

QUESTION

Is EFT vulnerable to the CVE-2024-6387 vulnerability?

ANSWER

No. This vulnerability only affects systems running on Linux. Additionally, this vulnerability only affects sshd, OpenSSH's server.

Therefore, since EFT only runs on Windows OSes and doesn't use sshd, this vulnerability isn't applicable to EFT.

MORE INFORMATION

Online article about discovery of vulnerability: https://www.scmagazine.com/news/14-million-openssh-servers-exposed-to-the-internet-via-regression-flaw

CVE website: https://nvd.nist.gov/vuln/detail/CVE-2024-6387