openssh: scp client improper directory name validation
Published Jan 10, 2019
5.3
MEDIUMCVSS 3.1
EPSS 3.68%
Description
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
Affected products
No data.
Configuration 2
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 3
- 8.0
- 9.0
Configuration 4
- 14.04
- 16.04
- 18.04
- 18.10
Configuration 5
- 7.0
- 8.0
- 8.1
- 8.2
- 8.4
- 8.6
- 8.2
- 8.4
- 8.6
- 8.2
- 8.4
- 8.6
Configuration 7
- < xcp2361
Configuration 8
- < xcp2361
Configuration 9
- < xcp2361
Configuration 10
- < xcp2361
Configuration 11
- < xcp2361
Configuration 12
- < xcp2361
Configuration 13
- < xcp3070
Configuration 14
- < xcp3070
Configuration 15
- < xcp3070
Configuration 16
- < xcp3070
Configuration 17
- < xcp3070
Configuration 18
- < xcp3070
Configuration 19
- < xcp3070
Configuration 20
- < 3.2.7
Running on/with
- n/a
Configuration 21
- < 3.2.7
Running on/with
- n/a
No data.
Red Hat Enterprise Linux 8
openssh-0:8.0p1-3.el8
Fixed · RHSA-2019:3702
Red Hat Enterprise Linux 8
openssh-0:8.0p1-3.el8
Fixed · RHSA-2019:3702
Red Hat Enterprise Linux 5
openssh
Out of support scope
Red Hat Enterprise Linux 6
openssh
Out of support scope
Red Hat Enterprise Linux 7
openssh
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | openssh-0:8.0p1-3.el8 | Fixed | RHSA-2019:3702 |
| Red Hat Enterprise Linux 8 | openssh-0:8.0p1-3.el8 | Fixed | RHSA-2019:3702 |
| Red Hat Enterprise Linux 5 | openssh | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | openssh | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | openssh | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the scp client shipped with openssh. The SSH protocol or the SSH client is not affected. For more detailed analysis please refer to: https://bugzilla.redhat.com/show_bug.cgi?id=1665785#c4
Red Hat mitigation
This issue only affects the users of scp binary which is a part of openssh-clients package. Other usage of SSH protocol or other ssh clients is not affected. Administrators can uninstall openssh-clients for additional protection against accidental usage of this binary. Removing the openssh-clients package will make binaries like scp and ssh etc unavailable on that system. Note: To exploit this flaw, the victim needs to connect to a malicious SSH server or MITM (Man-in-the-middle) the scp connection, both of which can be detected by the system administrator via a change in the host key of the SSH server. Further, if connections via scp are made to only trusted SSH servers, then those use-cases are not vulnerable to this security flaw.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
AV:N/AC:H/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Dec 17, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (37 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.68% (0.03681) | 89.32th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.68% (0.03681) | 88.21th | v5 (v2026.06.15) |
| Mar 4, 2026 | 3.38% (0.03377) | 87.15th | v4 (v2025.03.14) |
| Mar 1, 2026 | 2.07% (0.02066) | 83.71th | v4 (v2025.03.14) |
| Feb 4, 2026 | 3.38% (0.03377) | 87.07th | v4 (v2025.03.14) |
| Feb 1, 2026 | 2.07% (0.02066) | 83.60th | v4 (v2025.03.14) |
| Jan 4, 2026 | 3.38% (0.03377) | 87.02th | v4 (v2025.03.14) |
| Jan 1, 2026 | 2.07% (0.02066) | 83.53th | v4 (v2025.03.14) |
| Dec 4, 2025 | 3.38% (0.03377) | 86.94th | v4 (v2025.03.14) |
| Dec 1, 2025 | 2.07% (0.02066) | 83.43th | v4 (v2025.03.14) |
| Nov 21, 2025 | 3.38% (0.03377) | 86.90th | v4 (v2025.03.14) |
| Nov 18, 2025 | 0.80% (0.00801) | 71.95th | v4 (v2025.03.14) |
| Nov 4, 2025 | 3.38% (0.03377) | 86.87th | v4 (v2025.03.14) |
| Nov 1, 2025 | 2.07% (0.02066) | 83.39th | v4 (v2025.03.14) |
| Oct 4, 2025 | 3.10% (0.03097) | 86.28th | v4 (v2025.03.14) |
| Aug 30, 2025 | 1.93% (0.01927) | 82.64th | v4 (v2025.03.14) |
| Aug 4, 2025 | 3.25% (0.03249) | 86.64th | v4 (v2025.03.14) |
| Aug 1, 2025 | 2.21% (0.02208) | 83.88th | v4 (v2025.03.14) |
| Jul 4, 2025 | 3.74% (0.03744) | 87.52th | v4 (v2025.03.14) |
| Jul 1, 2025 | 2.10% (0.02105) | 83.36th | v4 (v2025.03.14) |
| Jun 4, 2025 | 3.44% (0.03441) | 86.92th | v4 (v2025.03.14) |
| Jun 1, 2025 | 2.10% (0.02105) | 83.27th | v4 (v2025.03.14) |
| May 4, 2025 | 3.47% (0.03469) | 86.90th | v4 (v2025.03.14) |
| May 1, 2025 | 2.12% (0.02123) | 83.24th | v4 (v2025.03.14) |
| Mar 30, 2025 | 3.47% (0.03469) | 86.44th | v4 (v2025.03.14) |
| Mar 29, 2025 | 5.34% (0.05339) | 83.07th | v4 (v2025.03.14) |
| Mar 17, 2025 | 3.47% (0.03469) | 86.76th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.38% (0.00383) | 73.89th | v3 (v2023.03.01) |
| Jun 2, 2024 | 0.49% (0.00488) | 76.05th | v3 (v2023.03.01) |
| May 3, 2024 | 0.69% (0.00686) | 79.95th | v3 (v2023.03.01) |
| Jan 4, 2024 | 0.69% (0.00686) | 77.91th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.71% (0.00712) | 78.03th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.48% (0.00484) | 72.23th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.69% (0.02686) | 62.66th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.88% (0.02880) | 63.65th | v5 (v2026.06.15) |
| Apr 14, 2021 | 2.88% (0.02880) | 0.00th | v1 |
References (18)
- http://www.securityfocus.com/bid/106531 vdb-entryBroken Link
- https://access.redhat.com/errata/RHSA-2019:3702 vendor-advisoryThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-20685 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1665785 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf PatchThird Party Advisory
- https://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/scp.c.diff?r1=1.197&r2=1.198&f=h Patch
- https://github.com/openssh/openssh-portable/commit/6010c0303a422a9c5fa8860c061bf7105eb7f8b2 Patch
- https://lists.debian.org/debian-lts-announce/2019/03/msg00030.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-20685
- https://security.gentoo.org/glsa/201903-16 vendor-advisoryThird Party Advisory
- https://security.gentoo.org/glsa/202007-53 vendor-advisoryThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190215-0001/ Third Party Advisory
- https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt PatchThird Party Advisory
- https://usn.ubuntu.com/3885-1/ vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-20685
- https://www.debian.org/security/2019/dsa-4387 vendor-advisoryThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html PatchThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html PatchThird Party Advisory
Change history (0)
No recorded changes yet.