Lucene search

K
cvelistMitreCVELIST:CVE-2020-15778
HistoryJul 24, 2020 - 12:00 a.m.

CVE-2020-15778

2020-07-2400:00:00
mitre
www.cve.org
21
openssh
scp
command injection
vulnerability

AI Score

7.9

Confidence

High

EPSS

0.006

Percentile

78.5%

scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of “anomalous argument transfers” because that could “stand a great chance of breaking existing workflows.”