Products
Platform
General
Public groups
Get answers from our community of experts in record time.
Hello all, do we know if MX appliances(Advanced License tier) already have snort rules 33654 and 63659 protecting against OpenSSH CVE-2024-6387? If so, is there public documentation I can refer and pass along?
Thank you!
You can find snort rule updates in the event log.
Search for: Event type include "Intrusion detection rules update"
There you should find the snort_rules_version_value.
I can't say specifically, but I can give you the rules for whether a signature is included or not, and from here, you should be able to work it out.
https://documentation.meraki.com/MX/Content_Filtering_and_Threat_Protection/Threat_Protection#Intrus...
From what I can see, the CVE has a score of 8.1.
https://nvd.nist.gov/vuln/detail/CVE-2024-6387
If you have the "Security" rule set selected then you should be covered.