CVE-2024-31497
published 2024-04-15CVE-2024-31497: In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in…
PriorityP338medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
5.77%
92.2th percentile
In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. This is especially important in a scenario where an adversary is able to read messages signed by PuTTY or Pageant. The required set of signed messages may be publicly readable because they are stored in a public Git service that supports use of SSH for commit signing, and the signatures were made by Pageant through an agent-forwarding mechanism. In other words, an adversary may already have enough signature information to compromise a victim's private key, even if there is no further use of vulnerable PuTTY versions. After a key compromise, an adversary may be able to conduct supply-chain attacks on software maintained in Git. A second, independent scenario is that the adversary is an operator of an SSH server to which the victim authenticates (for remote login or file copy), even though this server is not fully trusted by the victim, and the victim uses the same private key for SSH connections to other services operated by other entities. Here, the rogue server operator (who would otherwise have no way to determine the victim's private key) can derive the victim's private key, and then use it for unauthorized access to those other services. If the other services include Git services, then again it may be possible to conduct supply-chain attacks on software maintained in Git. This also affects, for example, FileZilla before 3.67.0, WinSCP before 6.3.3, TortoiseGit before 2.15.0.1, and TortoiseSVN through 1.14.6.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | filezilla | < filezilla 3.67.0-1 (forky) | filezilla 3.67.0-1 (forky) |
| debian | putty | < filezilla 3.67.0-1 (forky) | filezilla 3.67.0-1 (forky) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| filezilla-project | filezilla_client | < 3.67.0 | 3.67.0 |
| filezilla | filezilla | >= 0 < 3.67.0-1 | 3.67.0-1 |
| filezilla | filezilla | >= 0 < 3.67.0-1 | 3.67.0-1 |
| putty | putty | >= 0 < 0.74-1+deb11u2 | 0.74-1+deb11u2 |
| putty | putty | >= 0 < 0.78-2+deb12u2 | 0.78-2+deb12u2 |
| putty | putty | >= 0 < 0.81-1 | 0.81-1 |
| putty | putty | >= 0 < 0.81-1 | 0.81-1 |
| putty | putty | >= 0.68 < 0.81 | 0.81 |
| tigris | tortoisesvn | < 1.14.6 | 1.14.6 |
| tortoisegit | tortoisegit | < 2.15.0.1 | 2.15.0.1 |
| winscp | winscp | < 6.3.3 | 6.3.3 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2024-31497: filezilla - In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an ...
vendor_debian·2024·CVSS 5.9
CVE-2024-31497 [MEDIUM] CVE-2024-31497: filezilla - In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an ...
In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. This is especially important in a scenario where an adversary is able to read messages signed by PuTTY or Pageant. The required set of signed messages may be publicly readable because they are stored in a public Git service that supports use of SSH for commit signing, and the signatures were made by Pageant through an agent-forwarding mechanism. In other words, an adversary may already have enough signature information to compromise a victim's private key, even if there is no further use of vulnerable PuTTY versions. After a key compromise, an adversary may be able to conduct supply-chain attacks on software ma
OSV
CVE-2024-31497: In PuTTY 0
osv·2024-04-15·CVSS 5.9
CVE-2024-31497 [MEDIUM] CVE-2024-31497: In PuTTY 0
In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. This is especially important in a scenario where an adversary is able to read messages signed by PuTTY or Pageant. The required set of signed messages may be publicly readable because they are stored in a public Git service that supports use of SSH for commit signing, and the signatures were made by Pageant through an agent-forwarding mechanism. In other words, an adversary may already have enough signature information to compromise a victim's private key, even if there is no further use of vulnerable PuTTY versions. After a key compromise, an adversary may be able to conduct supply-chain attacks on software ma
GHSA
GHSA-6p4c-r453-8743: In PuTTY 0
ghsa_unreviewed·2024-04-15
CVE-2024-31497 GHSA-6p4c-r453-8743: In PuTTY 0
In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. This is especially important in a scenario where an adversary is able to read messages signed by PuTTY or Pageant. One scenario is that the adversary is an operator of an SSH server to which the victim authenticates (for remote login or file copy), even though this server is not fully trusted by the victim, and the victim uses the same private key for SSH connections to other services operated by other entities. Here, the rogue server operator (who would otherwise have no way to determine the victim's private key) can derive the victim's private key, and then use it for unauthorized access to those other servic
No detection rules found.
No public exploits indexed.
arXiv
On the Security of SSH Client Signatures
arxiv_cs_cr·2025-09-11·CVSS 5.9
[MEDIUM] On the Security of SSH Client Signatures
On the Security of SSH Client Signatures
Administrators and developers use SSH client keys and signatures for authentication, for example, to access internet backbone servers or to commit new code on platforms like GitHub. However, unlike servers, SSH clients cannot be measured through internet scans. We close this gap in two steps. First, we collect SSH client public keys. Such keys are regularly published by their owners on open development platforms like GitHub and GitLab. We systematize previous non-academic work by subjecting these keys to various security tests in a longitudinal study. Second, in a series of black-box lab experiments, we analyze the implementations of algorithms for SSH client signatures in 24 popular SSH clients for Linux, Windows, and macOS.
We extracted 31,622,33
Checkpoint
13th May – Threat Intelligence Report
blogs_checkpoint·2024-05-13
CVE-2024-4671 13th May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 13th May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 13th May, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Shared Services Connected Ltd, a payroll contractor for the UK Ministry of Defense has been breached, presumably by China. Around 270k records that include names and bank details of both current and past armed forces members were exposed.
US major healthcare operator Ascension, which operates 140 hospitals in 19 states, has disc
Bleepingcomputer
Citrix warns admins to manually mitigate PuTTY SSH client bug
blogs_bleepingcomputer·2024-05-09·CVSS 5.9
CVE-2024-31497 [MEDIUM] Citrix warns admins to manually mitigate PuTTY SSH client bug
## Citrix warns admins to manually mitigate PuTTY SSH client bug
## Sergiu Gatlan
Citrix notified customers this week to manually mitigate a PuTTY SSH client vulnerability that could allow attackers to steal a XenCenter admin's private SSH key.
XenCenter helps manage Citrix Hypervisor environments from a Windows desktop, including deploying and monitoring virtual machines.
The security flaw ( tracked as CVE-2024-31497 ) impacts multiple versions of XenCenter for Citrix Hypervisor 8.2 CU1 LTSR, which bundle and use PuTTY to make SSH connections from XenCenter to guest VMs when clicking the "Open SSH Console" button.
Citrix says that the PuTTY third-party component has been removed starting with XenCenter 8.2.6, and any versions after 8.2.7 will no longer include it.
"An issue has been
Bleepingcomputer
PuTTY SSH client flaw allows recovery of cryptographic private keys
blogs_bleepingcomputer·2024-04-16·CVSS 5.9
CVE-2024-31497 [MEDIUM] PuTTY SSH client flaw allows recovery of cryptographic private keys
## PuTTY SSH client flaw allows recovery of cryptographic private keys
## Bill Toulas
A vulnerability tracked as CVE-2024-31497 in PuTTY 0.68 through 0.80 could potentially allow attackers with access to 60 cryptographic signatures to recover the private key used for their generation.
PuTTY is a popular open-source terminal emulator, serial console, and network file transfer application that supports SSH (Secure Shell), Telnet, SCP (Secure Copy Protocol), and SFTP (SSH File Transfer Protocol).
System administrators and developers predominantly use the software to remotely access and manage servers and other networked devices over SSH from a Windows-based client.
The vulnerability tracked as CVE-2024-31497 was discovered by Fabian Bäumer and Marcus Brinkmann of the Ruhr University Boch
Wiz
CVE-2026-4115 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-4115 [HIGH] CVE-2026-4115 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4115 :
PuTTY vulnerability analysis and mitigation
A vulnerability was detected in PuTTY 0.83. Affected is the function eddsa_verify of the file crypto/ecc-ssh.c of the component Ed25519 Signature Handler. The manipulation results in improper verification of cryptographic signature. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit is now public and may be used. The real existence of this vulnerability is still doubted at the moment. The patch is identified as af996b5ec27ab79bae3882071b9d6acf16044549. It is advisable to implement a patch to correct this issue. The vendor was contacted early, responded in a very professional manner and quickly released a patch for the affected produc
Wiz
CVE-2023-53959 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.3
CVE-2023-53959 [MEDIUM] CVE-2023-53959 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-53959 :
FileZilla FTP Client vulnerability analysis and mitigation
FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll in the application directory. Attackers can generate a reverse shell payload using msfvenom and replace the missing DLL to achieve remote code execution when the application launches.
Source : NVD
## 8.5
Score
Published December 19, 2025
Severity HIGH
CNA Score 8.5
Affected Technologies
FileZilla FTP Client
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 52.7
Exploitation Probability (EPSS) 0.3
Affected packages and libraries
cpe:2.3:a:filezilla-project:filez
Wiz
CVE-2019-25683 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.3
CVE-2019-25683 [MEDIUM] CVE-2019-25683 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2019-25683 :
FileZilla FTP Client vulnerability analysis and mitigation
FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by supplying a malformed path string. Attackers can trigger the crash by entering a crafted path containing 384 'A' characters followed by 'BBBB' and 'CCCC' sequences in the search directory field and initiating a local search operation.
Source : NVD
## 6.9
Score
Published April 5, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
FileZilla FTP Client
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.6
Exploitation Probability (EPSS) N/A
Affected package
http://www.openwall.com/lists/oss-security/2024/04/15/6https://bugzilla.redhat.com/show_bug.cgi?id=2275183https://bugzilla.suse.com/show_bug.cgi?id=1222864https://docs.ccv.brown.edu/oscar/connecting-to-oscar/ssh/ssh-agent-forwarding/key-generation-and-agent-forwarding-with-puttyhttps://filezilla-project.org/versions.phphttps://git.tartarus.org/?h=c193fe9848f50a88a4089aac647fecc31ae96d27&p=simon/putty.githttps://github.com/advisories/GHSA-6p4c-r453-8743https://github.com/daedalus/BreakingECDSAwithLLLhttps://lists.debian.org/debian-lts-announce/2024/06/msg00014.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IZS3B37GNGWOOV7QU7B7JFK76U4TOP4V/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MMHILY2K7HQGQRHOC375KRRG2M6625RD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PUOTQVGC4DISVHQGSPUYGXO6TLDK65LA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WFDZBV7ZCAZ6AH3VCQ34SSY7L3J7VZXZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WMJH7M663BVO3SY6MFAW2FAZWLLXAPRQ/https://news.ycombinator.com/item?id=40044665https://security-tracker.debian.org/tracker/CVE-2024-31497https://securityonline.info/cve-2024-31497-critical-putty-vulnerability-exposes-private-keys-immediate-action-required/https://tartarus.org/~simon/putty-snapshots/htmldoc/Chapter9.html#pageant-forwardhttps://tortoisegit.orghttps://twitter.com/CCBalert/status/1780229237569470549https://twitter.com/lambdafu/status/1779969509522133272https://winscp.net/eng/news.phphttps://www.bleepingcomputer.com/news/security/putty-ssh-client-flaw-allows-recovery-of-cryptographic-private-keys/https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.htmlhttps://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.htmlhttps://www.openwall.com/lists/oss-security/2024/04/15/6https://www.reddit.com/r/sysadmin/comments/1c4wmoj/putty_vulnerability_affecting_v068_to_v08/http://www.openwall.com/lists/oss-security/2024/04/15/6https://bugzilla.redhat.com/show_bug.cgi?id=2275183https://bugzilla.suse.com/show_bug.cgi?id=1222864https://docs.ccv.brown.edu/oscar/connecting-to-oscar/ssh/ssh-agent-forwarding/key-generation-and-agent-forwarding-with-puttyhttps://filezilla-project.org/versions.phphttps://git.tartarus.org/?h=c193fe9848f50a88a4089aac647fecc31ae96d27&p=simon/putty.githttps://github.com/advisories/GHSA-6p4c-r453-8743https://github.com/daedalus/BreakingECDSAwithLLLhttps://lists.debian.org/debian-lts-announce/2024/06/msg00014.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IZS3B37GNGWOOV7QU7B7JFK76U4TOP4V/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MMHILY2K7HQGQRHOC375KRRG2M6625RD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PUOTQVGC4DISVHQGSPUYGXO6TLDK65LA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WFDZBV7ZCAZ6AH3VCQ34SSY7L3J7VZXZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WMJH7M663BVO3SY6MFAW2FAZWLLXAPRQ/https://lists.fedoraproject.org/archives/list/[email protected]/message/IZS3B37GNGWOOV7QU7B7JFK76U4TOP4V/https://lists.fedoraproject.org/archives/list/[email protected]/message/MMHILY2K7HQGQRHOC375KRRG2M6625RD/https://lists.fedoraproject.org/archives/list/[email protected]/message/PUOTQVGC4DISVHQGSPUYGXO6TLDK65LA/https://lists.fedoraproject.org/archives/list/[email protected]/message/WMJH7M663BVO3SY6MFAW2FAZWLLXAPRQ/https://news.ycombinator.com/item?id=40044665https://security-tracker.debian.org/tracker/CVE-2024-31497https://securityonline.info/cve-2024-31497-critical-putty-vulnerability-exposes-private-keys-immediate-action-required/https://tartarus.org/~simon/putty-snapshots/htmldoc/Chapter9.html#pageant-forwardhttps://tortoisegit.orghttps://twitter.com/CCBalert/status/1780229237569470549https://twitter.com/lambdafu/status/1779969509522133272https://winscp.net/eng/news.phphttps://www.bleepingcomputer.com/news/security/putty-ssh-client-flaw-allows-recovery-of-cryptographic-private-keys/https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.htmlhttps://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.htmlhttps://www.openwall.com/lists/oss-security/2024/04/15/6https://www.reddit.com/r/sysadmin/comments/1c4wmoj/putty_vulnerability_affecting_v068_to_v08/https://www.vicarius.io/vsociety/posts/understanding-a-critical-vulnerability-in-putty-biased-ecdsa-nonce-generation-revealing-nist-p-521-private-keys-cve-2024-31497
2024-04-15
Published