CVE-2019-14889 is a critical vulnerability in the libssh API function ssh_scp_new() affecting versions prior to 0.9.3 and 0.8.8, impacting various Linux distributions and libssh itself. This flaw allows for arbitrary command injection on the server-side if an attacker can influence the third parameter of the function. With a CVSS score of 8.8 (High), it presents a significant risk due to its network attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability compromise. While there is no evidence of active exploitation, no public exploit code, and it's not on the KEV catalog, there is some community discussion indicating interest in its exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.8.8CPE matchmatch criteria | cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:* | ||
>= 0.9.0, < 0.9.3CPE matchmatch criteria | cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | ||
19.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.