Man-in-the-Middle (MitM) attack in PuTTY - CVE-2020-14002

 

Man-in-the-Middle (MitM) attack in PuTTY - CVE-2020-14002

Published: July 2, 2020


Vulnerability identifier: #VU29487
CSH Severity: Medium
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14002
CWE-ID: CWE-300
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a Man-in-the-Middle (MitM) attack.

The vulnerability exists due to an observable discrepancy issue in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client).


Affected software

PuTTY
putty (Alpine package)
putty
Fedora

How to mitigate CVE-2020-14002

Install updates from vendor's website.

PuTTY - update to 0.74
putty - addressed in versions 0.74-1.el6, 0.74-1.el7, 0.74-1.fc31, 0.74-1.fc32

External References

Related Security Bulletins