CVE-2020-14002Observable Discrepancy in Putty

Severity
5.9MEDIUMNVD
EPSS
0.7%
top 26.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 29
Latest updateMay 24

Description

PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client).

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages3 packages

debiandebian/putty< putty 0.74-1 (bookworm)
Debianputty/putty< 0.74-1+3
NVDputty/putty0.680.73

Also affects: Fedora 31, 32

🔴Vulnerability Details

3
GHSA
GHSA-f25w-hjcw-x829: PuTTY 02022-05-24
OSV
CVE-2020-14002: PuTTY 02020-06-29
CVEList
CVE-2020-14002: PuTTY 02020-06-29

📋Vendor Advisories

1
Debian
CVE-2020-14002: putty - PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information ...2020

💬Community

4
Bugzilla
CVE-2020-14002 putty: Observable Discrepancy leading to an information leak in the algorithm negotiation2020-06-30
Bugzilla
CVE-2020-14002 putty: Observable Discrepancy leading to an information leak in the algorithm negotiation [fedora-all]2020-06-30
Bugzilla
CVE-2020-14002 putty: Observable Discrepancy leading to an information leak in the algorithm negotiation [epel-7]2020-06-30
Bugzilla
CVE-2020-14002 putty: Observable Discrepancy leading to an information leak in the algorithm negotiation [epel-6]2020-06-30