scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssh-keycatUpgrade openssh-askpassUpgrade pam_ssh_agent_authUpgrade openssh-clientsUpgrade opensshUpgrade openssh-serverUpgrade openssh-ldapUpgrade openssh-cavs | May 31, 2024 | Jul 24, 2020 |
| Alpine Linux | — | Upgrade openssh | Dec 1, 2025 | Jul 24, 2020 |
| Debian | — | No solution exists | May 15, 2025 | Jul 24, 2020 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 23, 2020 |
| Gentoo Linux | — | Upgrade net-misc/openssh. | Dec 29, 2022 | Jul 24, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openssh-clientsUpgrade openssh-keycatUpgrade openssh-cavsUpgrade opensshUpgrade openssh-askpassUpgrade openssh-serverUpgrade openssh-ldap | Jun 28, 2021 | Jul 24, 2020 |
| Openbsd Openssh | — | Upgrade to the latest version of OpenSSH | Jul 31, 2020 | Jul 24, 2020 |
| Oracle_linux | — | Upgrade opensshUpgrade openssh-keycatUpgrade openssh-clientsUpgrade pam_ssh_agent_authUpgrade openssh-askpassUpgrade openssh-ldapUpgrade openssh-cavsUpgrade openssh-server | May 29, 2024 | Jul 18, 2020 |
| Redhat_linux | — | Upgrade openssh-ldapUpgrade openssh-serverUpgrade openssh-clients-debuginfoUpgrade openssh-cavsUpgrade openssh-ldap-debuginfoUpgrade openssh-server-debuginfoUpgrade pam_ssh_agent_authUpgrade openssh-debuginfoUpgrade opensshUpgrade openssh-keycat-debuginfoUpgrade openssh-debugsourceUpgrade openssh-askpassUpgrade openssh-clientsUpgrade openssh-cavs-debuginfoUpgrade openssh-askpass-debuginfoNo solution existsUpgrade openssh-keycatUpgrade pam_ssh_agent_auth-debuginfo | May 23, 2024 | Jul 24, 2020 |
| Rocky_linux | — | Upgrade openssh-ldap-debuginfoUpgrade openssh-debuginfoUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-keycat-debuginfoUpgrade openssh-ldapUpgrade openssh-cavsUpgrade opensshUpgrade openssh-clients-debuginfoUpgrade openssh-serverUpgrade openssh-askpassUpgrade openssh-keycatUpgrade openssh-clientsUpgrade openssh-debugsourceUpgrade pam_ssh_agent_authUpgrade openssh-askpass-debuginfoUpgrade openssh-cavs-debuginfoUpgrade openssh-server-debuginfo | May 8, 2025 | Jul 24, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub