Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-6109

An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.091
EPSS Ranking 92.2%
CVSS Severity
CVSS v3 Score 6.8
CVSS v2 Score 4.0
References
Products affected by CVE-2019-6109


Contact Us

Shodan ® - All rights reserved