VYPR
Medium severity5.9NVD Advisory· Published Jun 29, 2020· Updated Jun 17, 2026

CVE-2020-14002

CVE-2020-14002

Description

PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:netapp:oncommand_unified_manager_core_package:-:*:*:*:*:*:*:*
  • Putty/Putty2 versions
    cpe:2.3:a:putty:putty:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:putty:putty:*:*:*:*:*:*:*:*range: >=0.68,<=0.73
    • (no CPE)range: 0.68 - 0.73
  • cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
  • PuTTY/PuTTYdescription

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.