CVE-2021-36367
This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user).
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.11%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user).
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
- EPSS
- 1.11% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-345
- Affected
- putty/putty
- Source
- cve@mitre.org
References
- https://git.tartarus.org/?p=simon/putty.git%3Ba=commit%3Bh=1dc5659aa62848f0aeb5de7bd3839fecc7debefa
- https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html
- https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.htmlRelease Notes, Third Party Advisory
- https://www.debian.org/security/2023/dsa-5588
- https://git.tartarus.org/?p=simon/putty.git%3Ba=commit%3Bh=1dc5659aa62848f0aeb5de7bd3839fecc7debefa
- https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html
- https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.htmlRelease Notes, Third Party Advisory
- https://www.debian.org/security/2023/dsa-5588
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.