CVE-2020-14002
MEDIUMPuTTY 0.68-0.73 - Information Leak via Algorithm Negotiation
Title source: llmDescription
PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client).
References (7)
Core 7
Core References
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/26TACCSQYYCPWAJYNAUIXJGZ5RGORJZV/
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JPV4A77EDCT4BTFO5BE26ZH72BG4E5IJ/
Mailing List mailing-list
https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html
Third Party Advisory
https://lists.tartarus.org/pipermail/putty-announce/
Third Party Advisory
https://security.netapp.com/advisory/ntap-20200717-0003/
Release Notes, Third Party Advisory
https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html
Scores
CVSS v3
5.9
EPSS
0.0075
EPSS Percentile
73.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-203
Status
published
Products (4)
fedoraproject/fedora
31
fedoraproject/fedora
32
netapp/oncommand_unified_manager_core_package
putty/putty
0.68 - 0.73
Published
Jun 29, 2020
Tracked Since
Feb 18, 2026