CVE-2020-15778 - CVE House
Back to Database
Status published Unknown CVE-2020-15778

scp in OpenSSH through 8.3p1 allows command injection in the...

Vulnerability Description

scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-15778

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

openssh, a700s firmware, active iq unified manager, hci management node, solidfire, steelstore cloud integrated storage, hci compute node, hci storage node, fabric operating system
Vulnerable Versions:
0, 8.3, 9.5

Timeline

Official Publish: July 24th, 2020
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.