Information Leak Vulnerability in PuTTY by Simon Tatham
CVE-2020-14002
5.9MEDIUM
What is CVE-2020-14002?
An information leak vulnerability exists in PuTTY versions 0.68 through 0.73 due to an observable discrepancy in the algorithm negotiation process. This weakness allows man-in-the-middle attackers to exploit initial connection attempts when the client has not yet cached a host key for the server. As a result, sensitive information may be exposed during the SSH setup, highlighting the importance of updating to secure versions.