CVE-2019-6110: Netapp Element Software

Medium severity, CVSS 6.8. EPSS: 20.9% chance of exploitation in the next 30 days.

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

Affected products

  • Netapp Element Software: affected versions not specified
  • Netapp Ontap Select Deploy: affected versions not specified
  • Netapp Storage Automation Store: affected versions not specified
  • OpenBSD OpenSSH: up to and including 7.9
  • Siemens Scalance x204rna Eec Firmware: before 3.2.7 (fixed in 3.2.7)
  • Siemens Scalance x204rna Firmware: before 3.2.7 (fixed in 3.2.7)
  • Winscp Winscp: up to and including 5.13

Published 2019-01-31. Last modified 2026-06-17.