CVE-2018-20685
published 2019-01-10CVE-2018-20685: In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact…
PriorityP185medium5.3CVSS 3.1
AVNACHPRNUIRSUCNIHAN
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
3.68%
88.4th percentile
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
Affected
53 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | dropbear | < dropbear 2020.79-1 (bookworm) | dropbear 2020.79-1 (bookworm) |
| debian | netkit-rsh | < netkit-rsh 0.17-20 (bookworm) | netkit-rsh 0.17-20 (bookworm) |
| debian | openssh | < openssh 1:7.9p1-5 (bookworm) | openssh 1:7.9p1-5 (bookworm) |
| dropbear_ssh_project | dropbear_ssh | < 2020.79 | 2020.79 |
| dropbear_ssh_project | dropbear_ssh | >= 0 < 2020.79-1 | 2020.79-1 |
| dropbear_ssh_project | dropbear_ssh | >= 0 < 2020.79-1 | 2020.79-1 |
| dropbear_ssh_project | dropbear_ssh | >= 0 < 2020.79-1 | 2020.79-1 |
| dropbear_ssh_project | dropbear_ssh | >= 0 < 2020.79-1 | 2020.79-1 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fujitsu | m10-1_firmware | < xcp2361 | xcp2361 |
| fujitsu | m10-1_firmware | < xcp3070 | xcp3070 |
| fujitsu | m10-4_firmware | < xcp2361 | xcp2361 |
| fujitsu | m10-4_firmware | < xcp3070 | xcp3070 |
| fujitsu | m10-4s_firmware | < xcp2361 | xcp2361 |
| fujitsu | m10-4s_firmware | < xcp3070 | xcp3070 |
| fujitsu | m12-1_firmware | < xcp2361 | xcp2361 |
| fujitsu | m12-1_firmware | < xcp3070 | xcp3070 |
Detection & IOCsextracted from sources · hover to see the quote
- →Malicious SSH/rsh server sends a filename of '.' or an empty filename during scp/rcp transfer to bypass access restrictions and modify target directory permissions on the client side ↗
- →Monitor scp client connections to untrusted or unexpected SSH servers; a change in the host key of the SSH server can indicate a malicious server or MITM attack exploiting this vulnerability ↗
- ·Only the scp binary (part of openssh-clients) is affected; the SSH protocol itself and other SSH clients are not impacted ↗
- ·Exploitation requires the victim to actively initiate an scp connection to a malicious or MITM'd server; connections to trusted SSH servers only are not vulnerable ↗
- ·PAN-OS versions affected: 7.1 before 7.1.26, 8.1 before 8.1.13, 9.0 before 9.0.7; PAN-OS 8.0 is end-of-life and no longer covered ↗
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vulncheck5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE X-200RNA Switch Devices
cisa_ics·2022-12-19
Siemens SCALANCE X-200RNA Switch Devices
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE X-200RNA Switch Devices
Last RevisedDecember 19, 2022
Alert CodeICSA-22-349-21
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available
- Vendor: Siemens
- Equipment: SCALANCE X-200RNA switch devices before V3.2.7
- Vulnerabilities: Observable Timing Discrepancy; Race Condition; Improper Restriction of Operations within the Bounds of a Memory Buffer; Improper Input Validation; NULL Pointer Dereference; Use After Free; Cryptographic Issues; Comparison of Incompatible Types; Resource Management
Red Hat
netkit-rsh: rcp access restriction bypass
vendor_redhat·2021-11-19·CVSS 5.3
CVE-2019-7282 [MEDIUM] CWE-281 netkit-rsh: rcp access restriction bypass
netkit-rsh: rcp access restriction bypass
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.
A vulnerability was found in rsh. The vulnerability occurs due to bypass restrictions via the filename of [.] or an empty filename. This flaw allows an attacker to modify the permissions of the target directory on the client-side.
Statement: Red Hat Enterprise Linux 6 and 7 were affected but Out of Support Scope.
https://access.redhat.com/support/policy/updates/errata/
Package: rsh (Red Hat Enterprise Linux 6) - Out of support scope
Package: rsh (Red Hat Enterprise Linux 7
Red Hat
krb5-appl: Improper directory name validation allows malicious server to bypass access restrictions
vendor_redhat·2021-02-02·CVSS 5.3
CVE-2019-25018 [MEDIUM] CWE-863 krb5-appl: Improper directory name validation allows malicious server to bypass access restrictions
krb5-appl: Improper directory name validation allows malicious server to bypass access restrictions
In the rcp client in MIT krb5-appl through 1.0.3, malicious servers could bypass intended access restrictions via the filename of . or an empty filename, similar to CVE-2018-20685 and CVE-2019-7282. The impact is modifying the permissions of the target directory on the client side. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.
Package: krb5-appl (Red Hat Enterprise Linux 6) - Out of support scope
Palo Alto
PAN-SA-2020-0002 PAN-OS: OpenSSH software upgraded to resolve multiple vulnerabilities
vendor_paloalto·2020-04-08·CVSS 5.3
[MEDIUM] CWE-20 PAN-SA-2020-0002 PAN-OS: OpenSSH software upgraded to resolve multiple vulnerabilities
PAN-SA-2020-0002 PAN-OS: OpenSSH software upgraded to resolve multiple vulnerabilities
OpenSSH software included with PAN-OS has been upgraded to resolve multiple vulnerabilities. These issue affects Palo Alto Networks PAN-OS 7.1 versions before 7.1.26; 8.1 versions before 8.1.13; 9.0 versions before 9.0.7. PAN-OS 8.0 is now end-of-life as of October 31, 2019, and is no longer covered by our Product Security Assurance policies. The resolved vulnerabilities include: CVE CVSS Summary CVE-2018-20685 5.3 ( CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N ) In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. CVE-2019-61
Debian
CVE-2020-36254: dropbear - scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filena...
vendor_debian·2020·CVSS 5.3
CVE-2020-36254 [MEDIUM] CVE-2020-36254: dropbear - scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filena...
scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685.
Scope: local
bookworm: resolved (fixed in 2020.79-1)
bullseye: resolved (fixed in 2020.79-1)
forky: resolved (fixed in 2020.79-1)
sid: resolved (fixed in 2020.79-1)
trixie: resolved (fixed in 2020.79-1)
Ubuntu
OpenSSH vulnerabilities
vendor_ubuntu·2019-02-07
CVE-2018-20685 OpenSSH vulnerabilities
Title: OpenSSH vulnerabilities
Summary: Several security issues were fixed in OpenSSH.
Harry Sintonen discovered multiple issues in the OpenSSH scp utility. If a
user or automated system were tricked into connecting to an untrusted
server, a remote attacker could possibly use these issues to write to
arbitrary files, change directory permissions, and spoof client output.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-7282: netkit-rsh - In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to byp...
vendor_debian·2019·CVSS 5.3
CVE-2019-7282 [MEDIUM] CVE-2019-7282: netkit-rsh - In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to byp...
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.
Scope: local
bookworm: resolved (fixed in 0.17-20)
bullseye: resolved (fixed in 0.17-20)
Red Hat
openssh: scp client improper directory name validation
vendor_redhat·2018-11-16·CVSS 5.3
CVE-2018-20685 [MEDIUM] CWE-20 openssh: scp client improper directory name validation
openssh: scp client improper directory name validation
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
Statement: This issue affects the scp client shipped with openssh. The SSH protocol or the SSH client is not affected. For more detailed analysis please refer to: https://bugzilla.redhat.com/show_bug.cgi?id=1665785#c4
Mitigation: This issue only affects the users of scp binary which is a part of openssh-clients package. Other usage of SSH protocol or other ssh clients is not affected. Administrators can uninstall openssh-clients for additional protection against accidental usage of this binary. Removing
Debian
CVE-2018-20685: openssh - In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass inte...
vendor_debian·2018·CVSS 5.3
CVE-2018-20685 [MEDIUM] CVE-2018-20685: openssh - In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass inte...
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
Scope: local
bookworm: resolved (fixed in 1:7.9p1-5)
bullseye: resolved (fixed in 1:7.9p1-5)
forky: resolved (fixed in 1:7.9p1-5)
sid: resolved (fixed in 1:7.9p1-5)
trixie: resolved (fixed in 1:7.9p1-5)
GHSA
GHSA-36m7-j2mr-5864: scp
ghsa_unreviewed·2022-05-24·CVSS 5.3
CVE-2020-36254 [MEDIUM] GHSA-36m7-j2mr-5864: scp
scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685.
GHSA
GHSA-xxwg-wfjg-vgjp: In the rcp client in MIT krb5-appl through 1
ghsa_unreviewed·2022-05-24·CVSS 5.3
CVE-2019-25018 [MEDIUM] CWE-863 GHSA-xxwg-wfjg-vgjp: In the rcp client in MIT krb5-appl through 1
In the rcp client in MIT krb5-appl through 1.0.3, malicious servers could bypass intended access restrictions via the filename of . or an empty filename, similar to CVE-2018-20685 and CVE-2019-7282. The impact is modifying the permissions of the target directory on the client side. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.
GHSA
GHSA-28hp-2gv6-gjp8: In OpenSSH 7
ghsa_unreviewed·2022-05-13
CVE-2018-20685 [MEDIUM] CWE-863 GHSA-28hp-2gv6-gjp8: In OpenSSH 7
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
GHSA
GHSA-xrxr-vcvh-gm7h: In NetKit through 0
ghsa_unreviewed·2022-04-30·CVSS 5.3
CVE-2019-7282 [MEDIUM] GHSA-xrxr-vcvh-gm7h: In NetKit through 0
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.
OSV
CVE-2020-36254: scp
osv·2021-02-25·CVSS 5.3
CVE-2020-36254 [MEDIUM] CVE-2020-36254: scp
scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685.
OSV
CVE-2019-7282: In NetKit through 0
osv·2019-01-31·CVSS 5.3
CVE-2019-7282 [MEDIUM] CVE-2019-7282: In NetKit through 0
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.
OSV
CVE-2018-20685: In OpenSSH 7
osv·2019-01-10·CVSS 5.3
CVE-2018-20685 [MEDIUM] CVE-2018-20685: In OpenSSH 7
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
VulnCheck
OpenBSD openssh Incorrect Authorization
vulncheck·2018·CVSS 5.3
CVE-2018-20685 [MEDIUM] OpenBSD openssh Incorrect Authorization
OpenBSD openssh Incorrect Authorization
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
Affected: OpenBSD openssh
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://cybersecurityworks.com/blog/cyber-risk/how-safe-are-enterprise-data-storage-systems.html; https://cybersecurityworks.com/blog/ransomware/cyber-hygiene-ransomware-is-causing-critical-care-disruption-in-hospitals.html; https://cybersecurity.bd.com/bulletins-and-patches/ry
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-20685 openssh: scp client improper directory name validation
bugzilla·2019-01-14·CVSS 5.3
CVE-2018-20685 [MEDIUM] CVE-2018-20685 openssh: scp client improper directory name validation
CVE-2018-20685 openssh: scp client improper directory name validation
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename.
Upstream Patch:
https://github.com/openssh/openssh-portable/commit/6010c030
https://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/scp.c.diff?r1=1.197&r2=1.198&f=h
Discussion:
Created openssh tracking bugs for this issue:
Affects: fedora-all [bug 1665786]
---
External References:
https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt
---
Analysis:
This is a flaw in the scp client (/usr/bin/scp) shipped as a part of openssh-clients package. The flaw essentially allows a malicious scp server to modify the permissions of the target directory by u
Bugzilla
CVE-2018-20685 openssh: scp client improper directory name validation [fedora-all]
bugzilla·2019-01-14·CVSS 5.3
CVE-2018-20685 [MEDIUM] CVE-2018-20685 openssh: scp client improper directory name validation [fedora-all]
CVE-2018-20685 openssh: scp client improper directory name validation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
http://www.securityfocus.com/bid/106531https://access.redhat.com/errata/RHSA-2019:3702https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/scp.c.diff?r1=1.197&r2=1.198&f=hhttps://github.com/openssh/openssh-portable/commit/6010c0303a422a9c5fa8860c061bf7105eb7f8b2https://lists.debian.org/debian-lts-announce/2019/03/msg00030.htmlhttps://security.gentoo.org/glsa/201903-16https://security.gentoo.org/glsa/202007-53https://security.netapp.com/advisory/ntap-20190215-0001/https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txthttps://usn.ubuntu.com/3885-1/https://www.debian.org/security/2019/dsa-4387https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttp://www.securityfocus.com/bid/106531https://access.redhat.com/errata/RHSA-2019:3702https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/scp.c.diff?r1=1.197&r2=1.198&f=hhttps://github.com/openssh/openssh-portable/commit/6010c0303a422a9c5fa8860c061bf7105eb7f8b2https://lists.debian.org/debian-lts-announce/2019/03/msg00030.htmlhttps://security.gentoo.org/glsa/201903-16https://security.gentoo.org/glsa/202007-53https://security.netapp.com/advisory/ntap-20190215-0001/https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txthttps://usn.ubuntu.com/3885-1/https://www.debian.org/security/2019/dsa-4387https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
2019-01-10
Published
Exploited in the wild