PT-2020-6182 · Openssh+7 · Openssh+7

·

CVE-2020-15778

·

Published

2020-07-18

·

Updated

2026-04-27

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSH versions through 8.3p1 OpenSSH (affected versions not specified) is also mentioned in relation to other products, but the primary focus is on OpenSSH through 8.3p1.
Description The issue allows command injection in the scp.c toremove function, as demonstrated by backtick characters in the destination argument. This could potentially allow a remote attacker to execute arbitrary commands. The vendor has reportedly stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
Recommendations For OpenSSH versions through 8.3p1: Consider disabling the toremove function in scp.c until a patch is available, or restrict the use of backtick characters in the destination argument to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:3166
ALSA-2024_1130
ALSA-2024_1150
ALSA-2024_3166
ALSA-2025_16880
ALT-PU-2021-2395
ALT-PU-2021-4855
ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
BDU:2021-03492
CESA-2024_3166
CVE-2020-15778
ECHO-D89C-9245-720B
ELSA-2024-3166
INFSA-2024_3166
OESA-2021-1377
RHSA-2024:3166
RHSA-2024_3166
RLSA-2024_3166

Affected Products

Alt Linux
Almalinux
Centos
Debian
Openssh
Red Hat
Red Os
Rocky Linux