Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-15778

30
FAUCET Score

CVE-2020-15778 describes a command injection vulnerability in the scp.c toremote function of OpenSSH through version 8.3p1, specifically when handling backtick characters in the destination argument. This flaw affects products from Broadcom, NetApp, and OpenBSD. With a CVSS score of 7.4 (High), it can be exploited via an adjacent network with low privileges and user interaction, potentially leading to high confidentiality, integrity, and availability impacts. While the vendor considers this an intentional omission for workflow compatibility, there is no evidence of active exploitation, readily available exploit code (Metasploit, Nuclei, ExploitDB), or significant media coverage, though it has seen some community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
< 8.3CPE matchmatch criteria
cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
8.3CPE matchmatch criteria
cpe:2.3:a:openbsd:openssh:8.3:-:*:*:*:*:*:*
8.3CPE matchmatch criteria
cpe:2.3:a:openbsd:openssh:8.3:p1:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:a700s_firmware:-:*:*:*:*:*:*:*
>= 9.5CPE matchmatch criteria
cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:*

CVSS Data

CVSS version used by this source: 3.1

7.4HIGH

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.5
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
13.00%
Probability of exploitation in next 30 days
EPSS Percentile
95.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.1300 is in the 100th percentile among its peer group of 18 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.4 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

microsoftpatch availablevia msrc
Product: 19166-16820Fixed in: -
microsoftpatch availablevia msrc
Product: cm1 openssh 8.0p1-12 on CBL Mariner 1.0Fixed in: -
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 8.0p1-12
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 8.0p1-12
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: openssh-0:8.0p1-24.el8
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openssh

Vendor Advisories (3)

microsoft2020-Sep/CVE-2020-15778

CVE-2020-15778

Sep 8, 2020
redhatCVE-2020-15778Moderate

openssh: scp allows command injection when using backtick characters in the destination argument

Jul 18, 2020
microsoft2020-Jul/CVE-2020-15778Important

scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."

Jul 14, 2020

References

access.redhat.com / errata/RHSA-2024:3166
Third Party Advisory
github.com / cpandya2909/CVE-2020-15778
ExploitThird Party Advisory
news.ycombinator.com / item
Third Party Advisory
security.gentoo.org / glsa/202212-06
Third Party Advisory
security.netapp.com / advisory/ntap-20200731-0007
Third Party Advisory
openssh.com / security.html
Vendor Advisory