A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user execute them under specific consequences.
This is the same issue as in OpenSSH, tracked as CVE-2019-6111.
CVSS Details
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)
- CVSS 3.0 Base Score: 5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-libsshalma-upgrade-libssh-configalma-upgrade-libssh-devel | May 27, 2026 | May 19, 2026 | |
| Alpine Linux | alpine-linux-upgrade-libssh | Apr 13, 2026 | Mar 26, 2026 | |
| Amazon_linux_2023 | amazon-linux-2023-upgrade-libsshamazon-linux-2023-upgrade-libssh-configamazon-linux-2023-upgrade-libssh-debuginfoamazon-linux-2023-upgrade-libssh-debugsourceamazon-linux-2023-upgrade-libssh-devel | Mar 27, 2026 | Feb 10, 2026 | |
| Redhat_linux | redhat-upgrade-libsshredhat-upgrade-libssh-configredhat-upgrade-libssh-debuginforedhat-upgrade-libssh-debugsourceredhat-upgrade-libssh-devel | May 20, 2026 | Feb 10, 2026 | |
| Rocky_linux | rocky-upgrade-libsshrocky-upgrade-libssh-debuginforocky-upgrade-libssh-debugsourcerocky-upgrade-libssh-devel | Jun 1, 2026 | May 28, 2026 | |
| Suse | suse-upgrade-libssh-configsuse-upgrade-libssh-develsuse-upgrade-libssh-devel-docsuse-upgrade-libssh4suse-upgrade-libssh4-32bit | Mar 4, 2026 | Feb 17, 2026 | |
| Ubuntu | ubuntu-pro-upgrade-libssh-4ubuntu-upgrade-libssh-4 | Feb 19, 2026 | Feb 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub