← back
CVE-2019-6111

CVE-2019-6111

CVSS 5.9 MEDIUMEPSS 58.2%CWE-22
Vexday Risk Score
45Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 5.9EPSS 58.2%KEV nãoPoC públicaNuclei Metasploit Patch referenciado
Lifecycle
11 Jan 2019Public PoC
31 Jan 2019Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →