Loading
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
Cite this page
CVE-2018-20685. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2018-20685
Use CWE-863, Openbsd vendor hub and Openssh product page to widen CVE-2018-20685 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-6387, CVE-2026-35385 and CVE-2023-51767 for nearby disclosures in the same product family.