#VU55005 Insufficient verification of data authenticity in PuTTY - CVE-2021-36367
Published: July 20, 2021
PuTTY
Simon Tatham
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to insufficient verification of data source when processing authentication responses. A remote attacker can send a spoofed authentication prompt even after an SSH session has been established with the original server and trick the victim into providing authentication credentials.