VDB

CVE-2019-6110

CVE-2019-6110 PUBLISHED CVSS 6.800000190734863 MEDIUM

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

EPSS 20.91% · 97.4th percentile

Risk Scores

CVSS 3.0
6.800000190734863
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS Score
20.91%
97.4th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSopenssh1:7.6p1-4ubuntu0.7+esm1, 1:7.6p1-4ubuntu0.7, 1:7.6p1-4ubuntu0.6
Ubuntu:18.04:LTSopenssh-ssh10, 1:7.5p1-9, 1:7.5p1-10
Ubuntu:20.04:LTSopenssh1:8.1p1-5, *, 1:8.2p1-4ubuntu0.13
Ubuntu:Pro:16.04:LTSopenssh*, 1:6.9p1-2, 1:6.9p1-3
Ubuntu:20.04:LTSopenssh-ssh1*, 0
Ubuntu:Pro:14.04:LTSopenssh*, *, *

Timeline

  • Jan 15, 2019 CVE Published
  • Jan 20, 2019 PoC Published
  • Mar 8, 2019 PoC Published
  • Jul 19, 2020 VulnCheck KEV Exploitation
  • Oct 2, 2020 PoC Published
  • Oct 15, 2020 VulnCheck KEV Exploitation
  • Nov 2, 2020 VulnCheck KEV Exploitation
  • Nov 6, 2020 PoC Published
  • Apr 14, 2021 EPSS Score
  • Sep 6, 2021 PoC Published
  • Dec 14, 2022 EPSS Score
  • Feb 14, 2023 VulnCheck KEV Exploitation
Open in Interactive Console →
$ Console Community · 100/wk Open console ›