CVE-2019-6110
ADVISORY - nistSummary
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.
EPSS Score: 0.55933 (0.980)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Inappropriate Encoding for Output Context
ADVISORY - redhat
User Interface (UI) Misrepresentation of Critical Information
NIST
CREATED
UPDATED
ADVISORY IDCVE-2019-6110
EXPLOITABILITY SCORE
1.6
EXPLOITS FOUND
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
6.8mediumDebian
CREATED
UPDATED
ADVISORY IDCVE-2019-6110
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AlowUbuntu
CREATED
UPDATED
ADVISORY IDCVE-2019-6110
EXPLOITABILITY SCORE
1.6
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
6.8lowRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2019-6110
EXPLOITABILITY SCORE
1.6
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
3.1lowintheWild
CREATED
UPDATED
ADVISORY IDCVE-2019-6110
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-