[WID-SEC-2023-1995] SCP in mehreren Produkten: Mehrere Schwachstellen CVSS Base Score 8.1 (hoch) CVSS Temporal Score 7.1 (hoch) Remoteangriff ja Datum 15.01.2019 Stand UPDATE 30.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Windows Produktbeschreibung OpenSSH ist eine Open Source Implementierung des Secure Shell Protokolls. WinSCP dient dem sicheren Dateitransfer auf Basis von SSH. PuTTY ist ein freier, Open Source Terminal Emulator der als Client für SSH, Telnet, rlogin und die Serielle Konsole dient. Produkte UPDATE 29.07.2026 RESF Rocky Linux UPDATE 16.12.2025 Open Source Dropbear SSH <2025.89 UPDATE 07.05.2024 EMC Avamar Dell NetWorker virtual UPDATE 01.05.2024 Broadcom Fabric OS <9.1.1d Broadcom Fabric OS <8.2.3e Broadcom Fabric OS <9.2.1 UPDATE 24.04.2024 HPE Switch UPDATE 16.04.2024 Broadcom Fabric OS <9.2.1 SolarWinds Security Event Manager <2024.2 Broadcom Fabric OS <9.2.0b Broadcom Fabric OS <9.1.1d UPDATE 08.08.2023 Amazon Linux 2 UPDATE 22.04.2020 F5 BIG-IP UPDATE 08.04.2020 Palo Alto Networks PAN-OS UPDATE 05.11.2019 Red Hat Enterprise Linux UPDATE 24.04.2019 Open Source Arch Linux UPDATE 10.02.2019 Debian Linux UPDATE 07.02.2019 Ubuntu Linux UPDATE 20.01.2019 SUSE Linux 15.01.2019 Open Source PuTTY Open Source OpenSSH <=7.9 Open Source WinSCP <5.14 Angriff Angriff Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in der SCP Komponente mehrerer Produkte ausnutzen um Daten offenzulegen und zu manipulieren. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple vulnerabilities in the SCP component of several SSH-related products, including OpenSSH, WinSCP, and PuTTY, allow a remote, anonymous attacker to disclose and manipulate data. The CVSS base score is 8.1 (High). Specific affected versions include OpenSSH up to and including 7.9, WinSCP prior to 5.14, and numerous other listed products and platforms, with many vendors having provided updates as noted in the article's timeline.