VRT 391,810 CVEs tracked · 15,472 in RASP scope · data as of 33 minutes ago

CVE-2000-0992

5.0 Medium Not applicable

Description

Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack.

Exploitation Status

Working exploit published

A reviewed exploit catalogue carries this CVE. Somebody has published code a stranger can run.

CVSS E:P

  • CISA KEV not listed
  • CISA Vulnrichment no assessment published
  • Indexed PoC 1 indexed Published artifacts you can open, in Exploit-DB; first seen 2000-09-30.
  • EPSS 5.7% chance in 30 days
IndexArtifactStarsFirst seen
Exploit-DB OpenSSH 1.2 - '.scp' File Create/Overwrite 2000-09-30

Waratek Defense Posture

Not applicable

Not a Java vulnerability. Outside ARMR's domain entirely.

  • Protection none
  • Action not-needed none
  • Review automated upstream-data
  • Record active
Decided by unmatched-product : No tracked product matched above, and none present at all
Finding Affected products (openbsd/openssh, ssh/ssh) are not in our known products list

CVSS

5.0 v2.0 AV:N/AC:L/Au:N/C:N/I:P/A:N 1 metric

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 2.0 5.0 no band published AV:N/AC:L/Au:N/C:N/I:P/A:N NVD Primary published

Affected Software & Releases

🖥️ Product CPEs & Version Ranges

2 product(s) over 20 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
nvd openbsd openssh generic 1.2 · 1.2.3
nvd ssh ssh generic 1.2.14 · 1.2.15 · 1.2.16 · 1.2.17 · 1.2.18 · 1.2.19 · 1.2.20 · 1.2.21 · 1.2.22 · 1.2.23 · 1.2.24 · 1.2.25 · 1.2.26 · 1.2.27 · 1.2.28 · 1.2.29 · 1.2.30 · 1.2.31

References

URLTags
http://archives.neohapsis.com/archives/bugtraq/2000-09/0359.html Exploit, Vendor Advisory
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:057
http://www.securityfocus.com/bid/1742 Exploit, Patch, Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/5312

Timeline

Published 2000-12-19 Last modified 2026-06-16
Published2000-12-19By the CVE Program.
NVD record modified2026-06-16NVD's own last-modified date for this record.