← back
CVE-2019-6110mediumobserved exploitationCWE-838

CVE-2019-6110

60Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 6.8epss 21%
from disclosure to weapon0 days
Published on NVDJan 31
1st PoCJan 11
VulnCheck+535d
exploitation probability
21%top 3% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.