CVE-2020-36254: Dropbear SSH Project Dropbear SSH
High severity, CVSS 8.1. EPSS: 1.9% chance of exploitation in the next 30 days.
scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685.
Affected products
- Dropbear SSH Project Dropbear SSH: before 2020.79 (fixed in 2020.79)
Published 2021-02-25. Last modified 2026-06-17.