ZeroHour

CVE-2019-6110

PoC
CVSS 3.1
6.8 medium
EPSS
21%p97
Published
()
Modified
Description

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

Vendors
openbsdwinscpnetappsiemens
Products
openssh, winscp, element software, ontap select deploy, storage automation store, scalance x204rna firmware, scalance x204rna eec firmware
Weakness
CWE-838
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

In the news