Skip to main content

CVE-2020-15778

7.4
HIGHCVSS v3.1 Base Score
64.28%
MEDIUM RiskEPSS (98th percentile)

scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."

Published: 7/24/2020
Modified: 7/28/2025
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.4HIGH

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

64.28%MEDIUM Exploitation Risk
98th percentile

This vulnerability has a 64.28% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.

Related Vulnerabilities