Skip to main content
Question

Open SSH Vulnerability

  • September 19, 2024
  • 3 replies
  • 1 view

Forum|alt.badge.img+1

For older Apple hardware that cannot run Mac OS Sonoma, how do you use jamf pro to install SSH version 9.8?

OpenSSH

Available for: macOS Sonoma

Impact: A remote attacker may be able to cause arbitrary code execution

Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.

CVE-2024-6387

 

mvu
Forum|alt.badge.img+20
  • Jamf Heroes
  • September 20, 2024

Was hoping macOS 14.7 patched this. This was updated with macOS 15.0.

 

May need to ask Apple.


AJPinto
Forum|alt.badge.img+26
  • Legendary Contributor
  • September 20, 2024

You don't. You need hardware standards and device refresh cycles. This is just the risk you must accept for running N-1 or even worse N-3 and older apple software.


sdagley
Forum|alt.badge.img+25
  • Jamf Heroes
  • September 20, 2024

This is an example of Apple's "Only the latest version of macOS will get all of the vulnerability fixes" policy in action. It would have been nice if they'd provided parity between 14.7 and 15.0 with security fixes, but nobody needs to delay upgrading their entire environment to macOS 15.0 right? <sarcasm/>


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings