CVE-2019-3463 describes a critical vulnerability in rssh, a restricted shell designed to limit users to rsync operations. Insufficient sanitization of rsync arguments allows attackers to bypass these restrictions and execute arbitrary shell commands. This vulnerability affects products from Canonical, Debian, Fedora Project, and PizzaShack. With a CVSS score of 9.8 (Critical), this vulnerability is easily exploitable over the network with low complexity, requiring no user interaction or privileges, and can lead to complete compromise of confidentiality, integrity, and availability. Its FAUCET Risk Score is 90/100, and its EPSS score indicates a higher than average likelihood of exploitation. Despite its high severity, there is no known active exploitation (not in KEV or Hot List), and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, with only one mention and one article, which oddly focuses on medical devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.3.4CPE matchmatch criteria | cpe:2.3:a:pizzashack:rssh:2.3.4:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
29CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.