In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade netkit-rsh | Nov 29, 2021 | Jan 31, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade rshUpgrade rsh-server | Jun 22, 2022 | Jan 31, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 31, 2019 |
| Ubuntu | — | Upgrade rsh-clientUpgrade rsh-server | Mar 16, 2022 | Jan 31, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub