
This script is a safe and simple tool that helps system users, students, and administrators check if their SCP (Secure Copy) client is vulnerable to CVE-2020-15778, a command injection vulnerability in OpenSSH SCP (versions ≤ 8.3p1).
CVE-2020-15778 is a command injection vulnerability discovered in the scp utility provided by OpenSSH (versions ≤ 8.3p1). The issue allows an attacker to execute arbitrary commands on the client system if a crafted destination argument (containing backticks) is passed to scp.
This repository includes a safe detection and simulation script written in Bash. The script helps users and system administrators:
scp version is vulnerableIn OpenSSH scp, versions up to 8.3p1 do not properly sanitize destination arguments before passing them to the shell. This allows an attacker to use shell metacharacters like backticks (`) to inject arbitrary commands.
scp file.txt user@host:`touch /tmp/pwned`/file.txt
In a vulnerable SCP version, this will execute touch /tmp/pwned on the client’s machine when the command runs.
| SCP Version | Status |
|---|---|
| ≤ 8.3p1 | Vulnerable |
| ≥ 8.4p1 | Not Vulnerable |
This Bash script performs the following actions:
git clone https://github.com/drackyjr/CVE-2020-15778-SCP-Command-Injection-Check.git
cd scp-cve-2020-15778-checker
chmod +x scp_cve_check.sh
./scp_cve_check.sh