CVE-2019-9898 — Use of Insufficiently Random Values in Putty
Severity
9.8CRITICALNVD
EPSS
4.3%
top 11.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 21
Latest updateMay 13
Description
Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages4 packages
Also affects: Debian Linux 8.0, 9.0, Fedora 28, 29
Patches
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2019-9898: putty - Potential recycling of random numbers used in cryptography exists within PuTTY b...↗2019