Use of a broken or risky cryptographic algorithm in OpenSSH - CVE-2020-14145

 

Use of a broken or risky cryptographic algorithm in OpenSSH - CVE-2020-14145

Published: July 30, 2020 / Updated: December 4, 2020


Vulnerability identifier: #VU32937
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14145
CWE-ID: CWE-327
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists in openssh client during algorithm negotiation due to observable discrepancy. A remote attacker can perform a Man-in-the-Middle (MitM) attack.


Affected software

OpenSSH
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
openEuler
IBM Integrated Analytics System
openssh (Alpine package)
pam_ssh_agent_auth
openssh (Red Hat package)
openssh-cavs
openssh-clients
openssh-keycat
openssh-ldap
openssh-server
openssh-askpass
openssh
RecoverPoint for Virtual Machines
Security Event Manager (SEM)
Red Hat Advanced Cluster Management for Kubernetes
QuTS hero
Dell EMC NetWorker vProxy
QNAP QTS
RSA Authentication Manager
Gaia

How to mitigate CVE-2020-14145

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Partial mitigation against this issue was included in OpenSSH 8.4


IBM Integrated Analytics System - update to 1.0.31.0
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
Security Event Manager (SEM) - update to 2024.2
QuTS hero - update to h5.1.8.2823 build 20240712
pam_ssh_agent_auth - update to 0.10.3-7.13.0.1
pam_ssh_agent_auth - update to 0.10.3-9.9
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
Dell EMC NetWorker vProxy - update to 4.3.0-12
QNAP QTS - update to 5.1.8.2823 20240712
openssh (Red Hat package) - update to 8.0p1-10.el8
openssh-cavs - update to 8.0p1-13.0.1
openssh-clients - update to 8.0p1-13.0.1
openssh-keycat - update to 8.0p1-13.0.1
openssh-ldap - update to 8.0p1-13.0.1
openssh-server - update to 8.0p1-13.0.1
openssh-askpass - update to 8.0p1-13.0.1
openssh - update to 8.0p1-13.0.1
RSA Authentication Manager - update to 8.5 Patch 3
Gaia - update to R81.10 Take 55

External References

Related Security Bulletins