Insufficient verification of data authenticity in PuTTY - CVE-2021-36367

 

Insufficient verification of data authenticity in PuTTY - CVE-2021-36367

Published: July 20, 2021


Vulnerability identifier: #VU55005
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-36367
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to insufficient verification of data source when processing authentication responses. A remote attacker can send a spoofed authentication prompt even after an SSH session has been established with the original server and trick the victim into providing authentication credentials.


Affected software

PuTTY
Arch Linux
Debian Linux
Fedora
putty (Debian package)
putty

How to mitigate CVE-2021-36367

Install updates from vendor's website.

PuTTY - update to 0.76
putty (Debian package) - addressed in versions 0.74-1+deb11u1, 0.78-2+deb12u1
putty - addressed in versions 0.76-1.el7, 0.76-1.el8

External References

Related Security Bulletins