Impact
An improper handling of destination paths in the scp utility of OpenSSH versions earlier than 10.4 can cause a transferred file to be written in the parent directory of the intended location when scp is used to copy between two remote hosts. This path‑traversal flaw (CWE‑22 and CWE‑23) allows an attacker to overwrite or create files in unintended locations, potentially affecting configuration files or system binaries, but does not provide arbitrary code execution. The impact is limited to the integrity of files on the target system and could lead to accidental or intentional file disruption.
Affected Systems
Systems running OpenBSD OpenSSH before 10.4p1 are affected. Any installation of OpenSSH whose version suffix does not indicate 10.4 or later should be considered vulnerable; administrators should verify the installed version and plan a replacement or upgrade accordingly.
Risk and Exploitability
The CVSS score of 4.2 indicates moderate severity. The EPSS score of less than 1% reflects a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV, suggesting no known large‑scale exploitation. The likely attack vector involves a remote attacker who can request scp to transfer a file between two hosts under their control; the attacker would force the target system to place the file in an unintended parent directory, potentially leading to accidental or intentional file disruption. No privilege escalation or code execution is required to exploit this flaw.
OpenCVE Enrichment
Ubuntu USN