PoC Index

CVE-2019-1000018

HIGH 7.8EPSS 1.9%

rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp permission that can result in Local command execution. This attack appear to be exploitable via An authorized SSH user with the allowscp permission.

CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS
1.88% chance of exploitation in the next 30 days, 78th percentile
Published
2019-02-04
Updated
2025-03-19

Proof-of-concept exploits (1)

References

Related