Skip to main content

Secure Copy Protocol Vulnerabilities

Several vulnerabilities have been identified which affect all implementations of Secure Copy Protocol (SCP). A remote attacker could exploit some of these vulnerabilities to make changes to an affected machine.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Several vulnerabilities have been identified which affect all implementations of Secure Copy Protocol (SCP). A remote attacker could exploit some of these vulnerabilities to make changes to an affected machine.


Threat details

SCP provides an authentication mechanism for transferring files across a network. It operates above Secure Shell and is a more secure implementation of Remote Copy Protocol.

The vulnerabilities can allow a malicious SCP server to:

  • Modify permissions of a target directory.
  • Overwrite arbitrary files in a target directory.
  • Hide malicious operations.

For further information:


Remediation steps

Type Step

Users and administrators are encouraged to review the Sintonen security advisory and apply the necessary updates.


Last edited: 14 February 2020 2:45 pm