Unrated severityNVD Advisory· Published Feb 4, 2019· Updated Mar 19, 2025
CVE-2019-1000018
CVE-2019-1000018
Description
rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp permission that can result in Local command execution. This attack appear to be exploitable via An authorized SSH user with the allowscp permission.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
10- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HO3MDU3AH5SLYBKHH5PJ6PHC63ASIF42/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KR2OHTHMJVV4DO3HDRFQQZ5JENHDJQEN/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T42YYNWJZG422GATWAHAEK4A24OKY557/mitrevendor-advisory
- security.gentoo.org/glsa/202007-29mitrevendor-advisory
- usn.ubuntu.com/3946-1/mitrevendor-advisory
- www.debian.org/security/2019/dsa-4377mitrevendor-advisory
- seclists.org/fulldisclosure/2021/May/78mitremailing-list
- lists.debian.org/debian-lts-announce/2019/01/msg00027.htmlmitremailing-list
- esnet-security.github.io/vulnerabilities/20190115_rsshmitre
- github.com/WlX-33/PoC-for-CVE/blob/main/CVE-2021-33216%2CCVE-2019-1000018/CommScope%20Ruckus%20IoT%20Controller%201.7.1.0%20Undocumented%20Account.txtmitre
News mentions
0No linked articles in our index yet.