CVE-2019-6110
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 20.9%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
- EPSS
- 20.91% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-838
- Affected
- openbsd/openssh · winscp/winscp · netapp/element software · netapp/ontap select deploy · netapp/storage automation store · siemens/scalance x204rna firmware · siemens/scalance x204rna eec firmware
- Source
- cve@mitre.org
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfPatch, Third Party Advisory
- https://cvsweb.openbsd.org/src/usr.bin/ssh/progressmeter.cRelease Notes
- https://cvsweb.openbsd.org/src/usr.bin/ssh/scp.cRelease Notes
- https://security.gentoo.org/glsa/201903-16Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190213-0001/Third Party Advisory
- https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txtThird Party Advisory
- https://www.exploit-db.com/exploits/46193/Exploit, Third Party Advisory, VDB Entry
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfPatch, Third Party Advisory
- https://cvsweb.openbsd.org/src/usr.bin/ssh/progressmeter.cRelease Notes
- https://cvsweb.openbsd.org/src/usr.bin/ssh/scp.cRelease Notes
- https://security.gentoo.org/glsa/201903-16Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190213-0001/Third Party Advisory
- https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txtThird Party Advisory
- https://www.exploit-db.com/exploits/46193/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.