Vulnerability record · CVE-2019-6111 · published 31 January 2019
CVE-2019-6111: OpenSSH scp client path traversal allows arbitrary file overwrite
Openbsd · Openssh
The scp client in OpenSSH 7.9 inherits its design from 1983 rcp, where the server decides which files and directories are sent. The client only performs cursory validation of returned object names, preventing directory traversal but not other malicious names, so a malicious scp server or man-in-the-middle can overwrite arbitrary files in the client's target directory. This matters because scp is widely used for trusted file transfer and the flaw breaks that trust assumption.
Description
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Automated analysis
high priorityPublic exploit code exists and EPSS is very high, but exploitation requires a malicious or man-in-the-middle server and the CVSS impact is limited to integrity (5.9).
What it is
The scp client in OpenSSH 7.9 inherits its design from 1983 rcp, where the server decides which files and directories are sent. The client only performs cursory validation of returned object names, preventing directory traversal but not other malicious names, so a malicious scp server or man-in-the-middle can overwrite arbitrary files in the client's target directory. This matters because scp is widely used for trusted file transfer and the flaw breaks that trust assumption.
Impact
An attacker controlling the scp server or positioned as a man-in-the-middle can overwrite arbitrary files in the client's target directory, and with recursive (-r) operation can manipulate subdirectories, for example overwriting .ssh/authorized_keys to gain persistent access.
Attack surface
Reached over the network via the scp protocol when a client connects to a malicious or compromised server, or when a man-in-the-middle intercepts the connection. No authentication or user interaction beyond initiating the scp transfer is required per the CVSS vector (AV:N/AC:H/PR:N/UI:N).
Exploitation
Not listed in CISA KEV, but EPSS is high (0.58204, 99.051 percentile) and references include Exploit tags (Bugzilla, Exploit-DB 46193), indicating public exploit code exists.
What to do
- Patch OpenSSH and affected products to versions containing the scp fix; apply vendor errata such as RHSA-2019:3702, USN-3885-1/2, DSA-4387, and FreeBSD-EN-19:10.scp.
- Where patching is not immediately possible, avoid scp for transfers from untrusted or untrusted-network servers and use sftp instead.
- Verify server host keys and use strict host key checking to reduce man-in-the-middle exposure.
- Restrict scp client use to trusted servers and monitor for unexpected file changes in target directories, especially .ssh/authorized_keys.
Detection
- Monitor for unexpected modifications to .ssh/authorized_keys and other sensitive files in directories used as scp targets.
- Audit scp client invocations and correlate with connections to untrusted or newly seen servers.
- Check for scp client versions prior to the fix and track patch status across OpenSSH and listed products.
- Review network traffic for scp sessions where the server sends filenames containing path separators or unexpected names.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
19 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-6111 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-6111), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.