CVE-2018-20685 - CVE House
Back to Database
Status published Unknown CVE-2018-20685

In OpenSSH 7.9, scp.c in the scp client allows remote...

Vulnerability Description

In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-20685

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

openssh, winscp, cloud backup, element software, ontap select deploy, steelstore cloud integrated storage, storage automation store, debian linux, ubuntu linux, enterprise linux, enterprise linux eus, enterprise linux server aus, enterprise linux server tus, solaris, m10-1 firmware, m10-4 firmware, m10-4s firmware, m12-1 firmware, m12-2 firmware, m12-2s firmware, scalance x204rna firmware, scalance x204rna eec firmware
Vulnerable Versions:
0, 8.0, 9.0, 14.04, 16.04, 18.04, 18.10, 7.0, 8.1, 8.2, 8.4, 8.6, 10

Timeline

Official Publish: January 10th, 2019
Last Modified: December 17th, 2025
Added to House: July 20th, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.