HIGH · 7.4

CVE-2020-15778

scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that th...

Vulnerability Description

scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."

CVSS Score

7.4

HIGH

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
OpenbsdOpenssh< 8.3
NetappA700S Firmware-
NetappA700S-
NetappActive Iq Unified Manager>= 9.5
NetappHci Management Node-
NetappSolidfire-
NetappSteelstore Cloud Integrated Storage-
NetappHci Compute Node-
NetappHci Storage Node-
BroadcomFabric Operating System-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-15778?

CVE-2020-15778 is a vulnerability with a CVSS score of 7.4 (HIGH). scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that th...

How severe is CVE-2020-15778?

CVE-2020-15778 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-15778?

Check the references section above for vendor advisories and patch information. Affected products include: Openbsd Openssh, Netapp A700S Firmware, Netapp A700S, Netapp Active Iq Unified Manager, Netapp Hci Management Node.