cbcvebase.
CVE-2020-15778
published 2020-07-24

CVE-2020-15778: scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE…

PriorityP347high7.4CVSS 3.1
AVAACLPRLUIRSUCHIHAH
EPSS
13.00%
95.9th percentile
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."

Affected

10 ranges
VendorProductVersion rangeFixed in
debiannetkit-rsh
debianopenssh
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_openssh_8.0p1-12_on_cbl_mariner_1.0
netappactive_iq_unified_manager>= 9.5
netkitnetkit
openbsdopenssh< 8.38.3
openbsdopenssh
paloaltopan-os

Detection & IOCsextracted from sources · hover to see the quote

  • Command injection in scp's toremote function is triggered by backtick characters in the destination argument; monitor scp invocations where the destination argument contains backtick (`) characters
  • The injected command executes with the permissions of the user account used for the scp transfer on the remote server; audit remote command execution events correlated with scp sessions
  • Only the scp binary is affected, not the SSH protocol or other openssh-clients binaries; scope detection to scp process execution specifically
  • A public proof-of-concept reproducer exists at https://github.com/cpandya2909/CVE-2020-15778; monitor for exploitation patterns derived from this PoC
  • ·The vendor (OpenSSH upstream) intentionally does not validate anomalous argument transfers in scp, meaning no upstream patch is planned; detection must rely on behavioral/argument monitoring rather than patched binary signatures
  • ·Red Hat Enterprise Linux 7 is marked 'Will not fix'; RHEL 8 received a fix via RHSA-2024:3166. Debian (bookworm, bullseye, forky, sid, trixie) remains open/unfixed as of available data
  • ·Exploitation requires the attacker to social-engineer or manipulate a user (ideally with elevated privileges) into running scp with a malicious destination argument; it is not a remote unauthenticated attack
  • ·The related CVE-2023-38336 affects netkit-rcp in rsh-client 0.17-24 via the same /bin/sh subsystem injection pattern; environments using rsh-client may also be exposed

CVSS provenance

nvdv3.17.4HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.4HIGH
vendor_msrc7.8HIGH
vendor_debian7.4LOW
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.