CVE-2021-36367

HIGH

PuTTY < 0.75 - Insufficient Verification of Data Authenticity

Title source: llm
STIX 2.1

Description

PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user).

Scores

CVSS v3 8.1
EPSS 0.0111
EPSS Percentile 61.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-345
Status published
Products (1)
putty/putty < 0.75
Published Jul 09, 2021
Tracked Since Feb 18, 2026