peter bassill · operator
$ cve CVE-2019-6111 JSON

CVE-2019-6111 EXPLOIT

5.9
MEDIUM · CVSS 3.1 · EPSS 58.2% (pctl 99)

Patch early

A public exploit exists.

Description

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

Scoring

CVSS5.9 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS58.2% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2019-01-31
Last modified2026-06-17

Affected (27)

VendorProduct
apachemina sshd
canonicalubuntu linux
debiandebian linux
fedoraprojectfedora
freebsdfreebsd
fujitsum10-1
fujitsum10-1 firmware
fujitsum10-4
fujitsum10-4 firmware
fujitsum10-4s
fujitsum10-4s firmware
fujitsum12-1
fujitsum12-1 firmware
fujitsum12-2
fujitsum12-2 firmware
fujitsum12-2s
fujitsum12-2s firmware
openbsdopenssh
redhatenterprise linux
redhatenterprise linux eus
redhatenterprise linux server aus
redhatenterprise linux server tus
siemensscalance x204rna
siemensscalance x204rna eec
siemensscalance x204rna eec firmware
siemensscalance x204rna firmware
winscpwinscp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD