PT-2021-11239 · Ssh2 · Ssh2

Erik Krogh Kristensen

+3

·

Published

2021-09-20

·

Updated

2021-10-01

·

CVE-2020-26301

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ssh2 versions prior to 1.4.0
Description: The issue is a command injection vulnerability that may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This issue only exists on Windows.
Recommendations: For versions prior to 1.4.0, update to version 1.4.0 to resolve the issue. As a temporary workaround, consider validating and sanitizing any untrusted input before calling the vulnerable method to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-26301
GHSA-652H-XWHF-Q4H6

Affected Products

Ssh2