In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:NNetapp Element Software
APPNetappall versionsNetapp Ontap Select Deploy
APPNetappall versionsNetapp Storage Automation Store
APPNetappall versionsOpenbsd OpenSSH
APPOpenbsd≤ 7.9Siemens Scalance X204rna
HWSiemensall versionsSiemens Scalance X204rna Eec
HWSiemensall versionsSiemens Scalance X204rna Eec Firmware
OSSiemens< 3.2.7Siemens Scalance X204rna Firmware
OSSiemens< 3.2.7Winscp
APPWinscp≤ 5.13
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
References
Related vulnerabilities
CVE-2023-38408CRITICAL9.8PL ✓same product
RCE w OpenSSH ssh-agent przez niezaufaną ścieżkę ładowania PKCS#11
CVE-2023-28531CRITICAL9.8PL ✓same product
OpenSSH ssh-add: brak ograniczeń destination constraints dla kluczy smartcard
CVE-2022-32207CRITICAL9.8PL ✓same product
curl: nieprawidłowe uprawnienia pliku przy zapisie cookies/alt-svc/hsts
CVE-2021-3331CRITICAL9.8PL ✓same product
WinSCP — zdalne wykonanie kodu przez spreparowany URL (sftp://)
CVE-2020-28864CRITICAL9.8PL ✓same product
Buffer overflow w WinSCP 5.17.8 — złośliwy serwer FTP może przejąć kontrolę