scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssh-cavsUpgrade openssh-ldapUpgrade openssh-serverUpgrade openssh-askpassUpgrade pam_ssh_agent_authUpgrade openssh-clientsUpgrade opensshUpgrade openssh-keycat | May 31, 2024 | Jul 24, 2020 |
| Alpine Linux | — | Upgrade openssh | Dec 1, 2025 | Jul 24, 2020 |
| Debian | — | No solution exists | May 15, 2025 | Jul 24, 2020 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 23, 2020 |
| Gentoo Linux | — | Upgrade net-misc/openssh. | Dec 29, 2022 | Jul 24, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openssh-keycatUpgrade openssh-clientsUpgrade openssh-askpassUpgrade openssh-ldapUpgrade opensshUpgrade openssh-cavsUpgrade openssh-server | Jun 28, 2021 | Jul 24, 2020 |
| Openbsd Openssh | — | Upgrade to the latest version of OpenSSH | Jul 31, 2020 | Jul 24, 2020 |
| Oracle_linux | — | Upgrade openssh-keycatUpgrade pam_ssh_agent_authUpgrade opensshUpgrade openssh-clientsUpgrade openssh-askpassUpgrade openssh-serverUpgrade openssh-cavsUpgrade openssh-ldap | May 29, 2024 | Jul 18, 2020 |
| Redhat_linux | — | Upgrade openssh-clients-debuginfoUpgrade pam_ssh_agent_authUpgrade opensshUpgrade openssh-debugsourceUpgrade openssh-keycat-debuginfoUpgrade openssh-ldap-debuginfoUpgrade openssh-debuginfoUpgrade openssh-cavsUpgrade openssh-serverUpgrade openssh-server-debuginfoUpgrade openssh-askpassUpgrade openssh-ldapUpgrade openssh-clientsUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-keycatNo solution existsUpgrade openssh-cavs-debuginfoUpgrade openssh-askpass-debuginfo | May 23, 2024 | Jul 24, 2020 |
| Rocky_linux | — | Upgrade openssh-cavs-debuginfoUpgrade openssh-debugsourceUpgrade openssh-server-debuginfoUpgrade openssh-clientsUpgrade openssh-askpass-debuginfoUpgrade pam_ssh_agent_authUpgrade openssh-keycatUpgrade openssh-keycat-debuginfoUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-cavsUpgrade openssh-askpassUpgrade openssh-serverUpgrade openssh-debuginfoUpgrade openssh-ldap-debuginfoUpgrade opensshUpgrade openssh-ldapUpgrade openssh-clients-debuginfo | May 8, 2025 | Jul 24, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub