WinSCP up to 5.13 scp core/ScpFileSystem.cpp TSCPFileSystem::SCPSink directory traversal

A vulnerability classified as problematic has been found in WinSCP up to 5.13. Affected is the function TSCPFileSystem::SCPSink of the file core/ScpFileSystem.cpp of the component scp. The manipulation with an unknown input leads to a directory traversal vulnerability. CWE is classifying the issue as CWE-22. This is going to have an impact on integrity, and availability.

The weakness was released 01/10/2019. This vulnerability is traded as CVE-2018-20684 since 01/10/2019. It is possible to launch the attack remotely. The exploitation doesn't require any form of authentication. Technical details are known, but there is no available exploit. The structure of the vulnerability defines a possible price range of USD $0-$5k at the moment (estimation calculated on 01/11/2019).

Upgrading to version 5.14 Beta eliminates this vulnerability.



Class: Directory traversal (CWE-22)
Local: No
Remote: Yes

Recommended: Upgrade
Upgrade: WinSCP 5.14 Beta


01/10/2019 Advisory disclosed
01/10/2019 CVE assigned
01/11/2019 VulDB entry created
01/11/2019 VulDB last update


CVE: CVE-2018-20684


Created: 01/11/2019
Événements SSI