Security Advisory

CVE-2018-20685

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-01-10 00:00:00
Last updated 2025-12-17 21:53:56
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.