CVE-2020-15778: Broadcom Fabric Operating System

High severity, CVSS 7.4. EPSS: 13% chance of exploitation in the next 30 days.

scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."

Affected products

  • Broadcom Fabric Operating System: affected versions not specified
  • Netapp a700s Firmware: affected versions not specified
  • Netapp Active Iq Unified Manager: from 9.5
  • Netapp Hci Compute Node: affected versions not specified
  • Netapp Hci Management Node: affected versions not specified
  • Netapp Hci Storage Node: affected versions not specified
  • Netapp Solidfire: affected versions not specified
  • Netapp Steelstore Cloud Integrated Storage: affected versions not specified
  • OpenBSD OpenSSH: before 8.3 (fixed in 8.3); version 8.3 only

Published 2020-07-24. Last modified 2026-06-17.