CVE-2019-6110 is a medium-severity vulnerability in OpenSSH 7.9 and related products like NetApp and WinSCP, where a malicious server or Man-in-the-Middle attacker can manipulate client output via arbitrary stderr content. This allows for the use of ANSI control codes to conceal additional file transfers, potentially leading to high confidentiality and integrity impacts. The attack requires user interaction and high attack complexity, but exploit code is publicly available through ExploitDB, though it is not listed on the KEV catalog and has minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.9CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* | ||
<= 5.13CPE matchmatch criteria | cpe:2.3:a:winscp:winscp:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:element_software:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:ontap_select_deploy:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:storage_automation_store:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.