ZeroHour

CVE-2020-14002

CVSS 3.1
5.9 medium
EPSS
3%p87
Published
()
Modified
Description

PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client).

Vendors
puttynetappfedoraproject
Products
putty, oncommand unified manager core package, fedora
Weakness
CWE-203
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.