5.3
CVE-2018-20685
- EPSS 3.74%
- Published 10.01.2019 21:29:00
- Last modified 21.11.2024 04:01:59
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
Data is provided by the National Vulnerability Database (NVD)
Netapp ≫ Cloud Backup Version-
Netapp ≫ Element Software Version-
Netapp ≫ Ontap Select Deploy Version-
Netapp ≫ Steelstore Cloud Integrated Storage Version-
Netapp ≫ Storage Automation Store Version-
Debian ≫ Debian Linux Version8.0
Debian ≫ Debian Linux Version9.0
Canonical ≫ Ubuntu Linux Version14.04 SwEditionlts
Canonical ≫ Ubuntu Linux Version16.04 SwEditionlts
Canonical ≫ Ubuntu Linux Version18.04 SwEditionlts
Canonical ≫ Ubuntu Linux Version18.10
Redhat ≫ Enterprise Linux Version7.0
Redhat ≫ Enterprise Linux Version8.0
Redhat ≫ Enterprise Linux Eus Version8.1
Redhat ≫ Enterprise Linux Eus Version8.2
Redhat ≫ Enterprise Linux Eus Version8.4
Redhat ≫ Enterprise Linux Eus Version8.6
Redhat ≫ Enterprise Linux Server Aus Version8.2
Redhat ≫ Enterprise Linux Server Aus Version8.4
Redhat ≫ Enterprise Linux Server Aus Version8.6
Redhat ≫ Enterprise Linux Server Tus Version8.2
Redhat ≫ Enterprise Linux Server Tus Version8.4
Redhat ≫ Enterprise Linux Server Tus Version8.6
Fujitsu ≫ M10-1 Firmware Version < xcp2361
Fujitsu ≫ M10-4 Firmware Version < xcp2361
Fujitsu ≫ M10-4s Firmware Version < xcp2361
Fujitsu ≫ M12-1 Firmware Version < xcp2361
Fujitsu ≫ M12-2 Firmware Version < xcp2361
Fujitsu ≫ M12-2s Firmware Version < xcp2361
Fujitsu ≫ M10-1 Firmware Version < xcp3070
Fujitsu ≫ M10-4 Firmware Version < xcp3070
Fujitsu ≫ M10-4s Firmware Version < xcp3070
Fujitsu ≫ M10-4s Firmware Version < xcp3070
Fujitsu ≫ M12-1 Firmware Version < xcp3070
Fujitsu ≫ M12-2 Firmware Version < xcp3070
Fujitsu ≫ M12-2s Firmware Version < xcp3070
Siemens ≫ Scalance X204rna Firmware Version < 3.2.7
Siemens ≫ Scalance X204rna Eec Firmware Version < 3.2.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 3.74% | 0.875 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.3 | 1.6 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 2.6 | 4.9 | 2.9 |
AV:N/AC:H/Au:N/C:N/I:P/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.