Impact
File names received via SCP in Apache MINA SSHD are not validated, allowing malicious senders to include directory traversal sequences such as '../'. This flaw permits an attacker to place files in arbitrary locations on the host, enabling overwriting critical files or installing malicious binaries, potentially leading to remote code execution or compromise of system integrity.
Affected Systems
Apache MINA SSHD clients or servers that use the older, unsupported releases below 2.0.0, and any applications built with MINA SSHD 2.0.0 or later that enable the SCP receive functionality. Hosts running MINA SSHD 2.0.0+ but that do not use the sshd-scp component are not affected.
Risk and Exploitability
The flaw is rated CVSS 7.5, indicating a high severity. The EPSS score is below 1 %, showing a low current exploitation probability, and the vulnerability is not listed in CISA KEV. The likely attack vector requires remote control of the SCP sender; the attacker must initiate a file transfer over SCP to exploit the path traversal. No known public exploits have been reported.
OpenCVE Enrichment