Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-20685

In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.037
EPSS Ranking 87.5%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 2.6
References
Products affected by CVE-2018-20685


Contact Us

Shodan ® - All rights reserved