V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2019-6110
DEB
LowConfirmedExploit available

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker)…

CVSS
3.1
Low
EPSS
0.21
p97
Published
2019-01-01
Updated
2019-01-01
Description

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

Tags · CWE
Pre-auth
CWE-451
CWE-838
CAPEC-98
CAPEC-154
CAPEC-163
CAPEC-164
CAPEC-173
CAPEC-468
Affected products
Element_softwareOntap_select_deployStorage_automation_store
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Timeline
2019-01-01
Published
2019-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: L
Low (L)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.209 · p97
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-163 · CWE-451
└ via CAPEC-98 · CWE-451
└ via CAPEC-163 · CWE-451
└ via CAPEC-163 · CWE-451
└ via CAPEC-163 · CWE-451
└ via CAPEC-98 · CWE-451
└ via CAPEC-163 · CWE-451
└ via CAPEC-163 · CWE-451
└ via CAPEC-163 · CWE-451
Known exploits — Сканер-ВС
46193
exploitdb · https://www.exploit-db.com/exploits/46193
Enterprise
46516
exploitdb · https://www.exploit-db.com/exploits/46516
Enterprise
Affected products
ProductVendorStatus
opensshTracked
opensshTracked
opensshTracked
opensshTracked
opensshTracked
opensshTracked
opensshTracked
opensshTracked
openssh-ssh1Tracked
openssh-ssh1Tracked
openssh-ssh1Tracked
openssh-ssh1Tracked
openssh-ssh1Tracked
element_software*Tracked
ontap_select_deploy*Tracked
openssh*Tracked
scalance_x204rna_eec_firmware*Tracked
scalance_x204rna_firmware*Tracked
storage_automation_store*Tracked
winscp*Tracked
Source databases
DEB
CVE
UBU
Related vulnerabilities