Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wccm-6vx2-7p8c

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user).

PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user).

EPSS

Процентиль: 34%
0.00135
Низкий

8.1 High

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 4 лет назад

PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user).

CVSS3: 8.1
nvd
больше 4 лет назад

PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user).

CVSS3: 8.1
debian
больше 4 лет назад

PuTTY through 0.75 proceeds with establishing an SSH session even if i ...

CVSS3: 8.1
fstec
больше 4 лет назад

Уязвимость реализации протокола SSH средства криптографической защиты PuTTY, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 34%
0.00135
Низкий

8.1 High

CVSS3

Дефекты

CWE-345