CVE-2020-14002

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/06/2020
Last modified:
25/04/2024

Description

PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:putty:putty:*:*:*:*:*:*:*:* 0.68 (including) 0.73 (including)
cpe:2.3:a:netapp:oncommand_unified_manager_core_package:-:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*