cbcvebase.
CVE-2018-20685
published 2019-01-10

CVE-2018-20685: In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact…

PriorityP185medium5.3CVSS 3.1
AVNACHPRNUIRSUCNIHAN
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
3.68%
88.4th percentile
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.

Affected

53 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandropbear< dropbear 2020.79-1 (bookworm)dropbear 2020.79-1 (bookworm)
debiannetkit-rsh< netkit-rsh 0.17-20 (bookworm)netkit-rsh 0.17-20 (bookworm)
debianopenssh< openssh 1:7.9p1-5 (bookworm)openssh 1:7.9p1-5 (bookworm)
dropbear_ssh_projectdropbear_ssh< 2020.792020.79
dropbear_ssh_projectdropbear_ssh>= 0 < 2020.79-12020.79-1
dropbear_ssh_projectdropbear_ssh>= 0 < 2020.79-12020.79-1
dropbear_ssh_projectdropbear_ssh>= 0 < 2020.79-12020.79-1
dropbear_ssh_projectdropbear_ssh>= 0 < 2020.79-12020.79-1
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
fujitsum10-1_firmware< xcp2361xcp2361
fujitsum10-1_firmware< xcp3070xcp3070
fujitsum10-4_firmware< xcp2361xcp2361
fujitsum10-4_firmware< xcp3070xcp3070
fujitsum10-4s_firmware< xcp2361xcp2361
fujitsum10-4s_firmware< xcp3070xcp3070
fujitsum12-1_firmware< xcp2361xcp2361
fujitsum12-1_firmware< xcp3070xcp3070

Detection & IOCsextracted from sources · hover to see the quote

  • Malicious SSH/rsh server sends a filename of '.' or an empty filename during scp/rcp transfer to bypass access restrictions and modify target directory permissions on the client side
  • Monitor scp client connections to untrusted or unexpected SSH servers; a change in the host key of the SSH server can indicate a malicious server or MITM attack exploiting this vulnerability
  • ·Only the scp binary (part of openssh-clients) is affected; the SSH protocol itself and other SSH clients are not impacted
  • ·Exploitation requires the victim to actively initiate an scp connection to a malicious or MITM'd server; connections to trusted SSH servers only are not vulnerable
  • ·PAN-OS versions affected: 7.1 before 7.1.26, 8.1 before 8.1.13, 9.0 before 9.0.7; PAN-OS 8.0 is end-of-life and no longer covered

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vulncheck5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.