scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssh-askpassUpgrade openssh-keycatUpgrade opensshUpgrade pam_ssh_agent_authUpgrade openssh-clientsUpgrade openssh-cavsUpgrade openssh-ldapUpgrade openssh-server | May 31, 2024 | Jul 24, 2020 |
| Alpine Linux | — | Upgrade openssh | Dec 1, 2025 | Jul 24, 2020 |
| Debian | — | No solution exists | May 15, 2025 | Jul 24, 2020 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 23, 2020 |
| Gentoo Linux | — | Upgrade net-misc/openssh. | Dec 29, 2022 | Jul 24, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openssh-serverUpgrade openssh-cavsUpgrade opensshUpgrade openssh-askpassUpgrade openssh-ldapUpgrade openssh-keycatUpgrade openssh-clients | Jun 28, 2021 | Jul 24, 2020 |
| Openbsd Openssh | — | Upgrade to the latest version of OpenSSH | Jul 31, 2020 | Jul 24, 2020 |
| Oracle_linux | — | Upgrade pam_ssh_agent_authUpgrade openssh-keycatUpgrade opensshUpgrade openssh-clientsUpgrade openssh-cavsUpgrade openssh-ldapUpgrade openssh-askpassUpgrade openssh-server | May 29, 2024 | Jul 18, 2020 |
| Redhat_linux | — | Upgrade openssh-cavs-debuginfoNo solution existsUpgrade openssh-askpass-debuginfoUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-keycatUpgrade openssh-clientsUpgrade openssh-keycat-debuginfoUpgrade openssh-debuginfoUpgrade openssh-ldapUpgrade openssh-ldap-debuginfoUpgrade openssh-askpassUpgrade openssh-server-debuginfoUpgrade openssh-debugsourceUpgrade pam_ssh_agent_authUpgrade openssh-serverUpgrade opensshUpgrade openssh-clients-debuginfoUpgrade openssh-cavs | May 23, 2024 | Jul 24, 2020 |
| Rocky_linux | — | Upgrade openssh-askpass-debuginfoUpgrade pam_ssh_agent_authUpgrade openssh-debugsourceUpgrade openssh-clientsUpgrade openssh-server-debuginfoUpgrade openssh-cavs-debuginfoUpgrade openssh-clients-debuginfoUpgrade openssh-cavsUpgrade openssh-keycat-debuginfoUpgrade openssh-ldapUpgrade openssh-ldap-debuginfoUpgrade openssh-debuginfoUpgrade openssh-askpassUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-keycatUpgrade opensshUpgrade openssh-server | May 8, 2025 | Jul 24, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub