Search/CVE-2018-20685
CVE — Medium

CVE-2018-20685

In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.

CVSS v3.1
5.3 MEDIUM
EPSS
3.68%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
Timeline
disclosure → media coverage
Jan 10, 2019
Disclosure — published as a CVE record. · last revised by NVD Dec 17, 2025