CVE-2020-15778
published 2020-07-24CVE-2020-15778: scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE…
PriorityP347high7.4CVSS 3.1
AVAACLPRLUIRSUCHIHAH
EPSS
13.00%
95.9th percentile
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | netkit-rsh | — | — |
| debian | openssh | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_openssh_8.0p1-12_on_cbl_mariner_1.0 | — | — |
| netapp | active_iq_unified_manager | >= 9.5 | — |
| netkit | netkit | — | — |
| openbsd | openssh | < 8.3 | 8.3 |
| openbsd | openssh | — | — |
| paloalto | pan-os | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Command injection in scp's toremote function is triggered by backtick characters in the destination argument; monitor scp invocations where the destination argument contains backtick (`) characters ↗
- →The injected command executes with the permissions of the user account used for the scp transfer on the remote server; audit remote command execution events correlated with scp sessions ↗
- →Only the scp binary is affected, not the SSH protocol or other openssh-clients binaries; scope detection to scp process execution specifically ↗
- →A public proof-of-concept reproducer exists at https://github.com/cpandya2909/CVE-2020-15778; monitor for exploitation patterns derived from this PoC ↗
- ·The vendor (OpenSSH upstream) intentionally does not validate anomalous argument transfers in scp, meaning no upstream patch is planned; detection must rely on behavioral/argument monitoring rather than patched binary signatures ↗
- ·Red Hat Enterprise Linux 7 is marked 'Will not fix'; RHEL 8 received a fix via RHSA-2024:3166. Debian (bookworm, bullseye, forky, sid, trixie) remains open/unfixed as of available data ↗
- ·Exploitation requires the attacker to social-engineer or manipulate a user (ideally with elevated privileges) into running scp with a malicious destination argument; it is not a remote unauthenticated attack ↗
- ·The related CVE-2023-38336 affects netkit-rcp in rsh-client 0.17-24 via the same /bin/sh subsystem injection pattern; environments using rsh-client may also be exposed ↗
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.4HIGH
vendor_msrc7.8HIGH
vendor_debian7.4LOW
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vg2g-72mx-mj33: netkit-rcp in rsh-client 0
ghsa_unreviewed·2023-07-15·CVSS 4.6
CVE-2023-38336 [MEDIUM] CWE-77 GHSA-vg2g-72mx-mj33: netkit-rcp in rsh-client 0
netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-2019-7283, and CVE-2020-15778.
OSV
CVE-2023-38336: netkit-rcp in rsh-client 0
osv·2023-07-14·CVSS 4.6
CVE-2023-38336 [MEDIUM] CVE-2023-38336: netkit-rcp in rsh-client 0
netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-2019-7283, and CVE-2020-15778.
GHSA
GHSA-cvxm-8hgf-6m6m: scp in OpenSSH through 8
ghsa_unreviewed·2022-05-24
CVE-2020-15778 [MEDIUM] CWE-78 GHSA-cvxm-8hgf-6m6m: scp in OpenSSH through 8
scp in OpenSSH through 8.3p1 allows command injection in scp.c remote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
OSV
CVE-2020-15778: scp in OpenSSH through 8
osv·2020-07-24·CVSS 7.4
CVE-2020-15778 [HIGH] CVE-2020-15778: scp in OpenSSH through 8
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Debian
CVE-2023-38336: netkit-rsh - netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because ...
vendor_debian·2023·CVSS 4.6
CVE-2023-38336 [MEDIUM] CVE-2023-38336: netkit-rsh - netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because ...
netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-2019-7283, and CVE-2020-15778.
Scope: local
bookworm: open
bullseye: open
Red Hat
openssh: scp allows command injection when using backtick characters in the destination argument
vendor_redhat·2020-07-18·CVSS 7.4
CVE-2020-15778 [HIGH] CWE-77 openssh: scp allows command injection when using backtick characters in the destination argument
openssh: scp allows command injection when using backtick characters in the destination argument
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
A flaw was found in the scp program shipped with the openssh-clients package. An attacker having the ability to scp files to a remote server, could execute arbitrary commands on the remote server by including the command as a part of the filename being copied on the server. This command is run with the permissions of user with which the files were copied on
Microsoft
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that the
vendor_msrc·2020-07-14·CVSS 7.8
CVE-2020-15778 [HIGH] CWE-78 scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that the
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publi
Debian
CVE-2020-15778: openssh - scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote func...
vendor_debian·2020·CVSS 7.4
CVE-2020-15778 [HIGH] CVE-2020-15778: openssh - scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote func...
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-15778 openssh: scp allows command injection when using backtick characters in the destination argument [fedora-all]
bugzilla·2020-07-24·CVSS 7.4
CVE-2020-15778 [HIGH] CVE-2020-15778 openssh: scp allows command injection when using backtick characters in the destination argument [fedora-all]
CVE-2020-15778 openssh: scp allows command injection when using backtick characters in the destination argument [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
Bugzilla
CVE-2020-15778 openssh: scp allows command injection when using backtick characters in the destination argument
bugzilla·2020-07-24·CVSS 7.4
CVE-2020-15778 [HIGH] CVE-2020-15778 openssh: scp allows command injection when using backtick characters in the destination argument
CVE-2020-15778 openssh: scp allows command injection when using backtick characters in the destination argument
scp in OpenSSH through 8.3p1 allows command injection in scp.c remote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
Reference:
https://www.openssh.com/security.html
Discussion:
Created openssh tracking bugs for this issue:
Affects: fedora-all [bug 1860488]
---
Reproducer: https://github.com/cpandya2909/CVE-2020-15778
Can be reproduce in 1 minute.
---
External References:
https://access.redhat.com/articles/5284081
https://github.com/cpandya2909/CVE-2020-15
https://access.redhat.com/errata/RHSA-2024:3166https://github.com/cpandya2909/CVE-2020-15778/https://news.ycombinator.com/item?id=25005567https://security.gentoo.org/glsa/202212-06https://security.netapp.com/advisory/ntap-20200731-0007/https://www.openssh.com/security.htmlhttps://access.redhat.com/errata/RHSA-2024:3166https://github.com/cpandya2909/CVE-2020-15778/https://news.ycombinator.com/item?id=25005567https://security.gentoo.org/glsa/202212-06https://security.netapp.com/advisory/ntap-20200731-0007/https://www.openssh.com/security.html
2020-07-24
Published