CVE-2021-36367
published 2021-07-09CVE-2021-36367: PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an…
PriorityP345high8.1CVSS 3.1
AVNACLPRNUIRSUCHIHAN
EPSS
1.11%
62.0th percentile
PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | putty | < putty 0.75-3 (bookworm) | putty 0.75-3 (bookworm) |
| putty | putty | <= 0.75 | — |
| putty | putty | >= 0 < 0.74-1+deb11u1 | 0.74-1+deb11u1 |
| putty | putty | >= 0 < 0.75-3 | 0.75-3 |
| putty | putty | >= 0 < 0.75-3 | 0.75-3 |
| putty | putty | >= 0 < 0.75-3 | 0.75-3 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv8.1HIGH
vendor_debian8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wccm-6vx2-7p8c: PuTTY through 0
ghsa_unreviewed·2022-05-24
CVE-2021-36367 [HIGH] CWE-345 GHSA-wccm-6vx2-7p8c: PuTTY through 0
PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user).
OSV
CVE-2021-36367: PuTTY through 0
osv·2021-07-09·CVSS 8.1
CVE-2021-36367 [HIGH] CVE-2021-36367: PuTTY through 0
PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user).
Debian
CVE-2021-36367: putty - PuTTY through 0.75 proceeds with establishing an SSH session even if it has neve...
vendor_debian·2021·CVSS 8.1
CVE-2021-36367 [HIGH] CVE-2021-36367: putty - PuTTY through 0.75 proceeds with establishing an SSH session even if it has neve...
PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user).
Scope: local
bookworm: resolved (fixed in 0.75-3)
bullseye: resolved (fixed in 0.74-1+deb11u1)
forky: resolved (fixed in 0.75-3)
sid: resolved (fixed in 0.75-3)
trixie: resolved (fixed in 0.75-3)
No detection rules found.
No public exploits indexed.
https://git.tartarus.org/?p=simon/putty.git%3Ba=commit%3Bh=1dc5659aa62848f0aeb5de7bd3839fecc7debefahttps://lists.debian.org/debian-lts-announce/2024/04/msg00016.htmlhttps://www.chiark.greenend.org.uk/~sgtatham/putty/changes.htmlhttps://www.debian.org/security/2023/dsa-5588https://git.tartarus.org/?p=simon/putty.git%3Ba=commit%3Bh=1dc5659aa62848f0aeb5de7bd3839fecc7debefahttps://lists.debian.org/debian-lts-announce/2024/04/msg00016.htmlhttps://www.chiark.greenend.org.uk/~sgtatham/putty/changes.htmlhttps://www.debian.org/security/2023/dsa-5588
2021-07-09
Published