CVE-2020-15778 | OpenSSH up to 8.3p1 scp scp.c destination os command injection (Nessus ID 235514)
A vulnerability was found in OpenSSH up to 8.3p1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file scp.c of the component scp. The manipulation of the argument destination as part of Backtick leads to os command injection.
This vulnerability is known as CVE-2020-15778. The attack can be launched remotely. There is no exploit available.
The real existence of this vulnerability is still doubted at the moment.
It is recommended to disable the affected component.