ZeroHour

CVE-2020-15778

PoC
CVSS 3.1
7.4 high
EPSS
13%p96
Published
()
Modified
Description

scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."

Vendors
openbsdnetappbroadcom
Products
openssh, a700s firmware, active iq unified manager, hci management node, solidfire, steelstore cloud integrated storage, hci compute node, hci storage node, fabric operating system
Weakness
CWE-78
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.