Man-in-the-Middle (MitM) attack in PuTTY - CVE-2020-14002
Published: July 2, 2020
Vulnerability identifier: #VU29487
CSH Severity: Medium
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14002
CWE-ID: CWE-300
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a Man-in-the-Middle (MitM) attack.
The vulnerability exists due to an observable discrepancy issue in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client).
Affected software
PuTTY
putty (Alpine package)
putty
Fedora
putty (Alpine package)
putty
Fedora
How to mitigate CVE-2020-14002
Install updates from vendor's website.
PuTTY - update to 0.74
putty - addressed in versions 0.74-1.el6, 0.74-1.el7, 0.74-1.fc31, 0.74-1.fc32
putty - addressed in versions 0.74-1.el6, 0.74-1.el7, 0.74-1.fc31, 0.74-1.fc32