QID 375759

Date Published: 2021-08-04

QID 375759: Putty Multiple Security Vulnerabilities

PuTTY is a client program for the SSH, Telnet and Rlogin network protocols. It is integrated in multiple applications on multiple operating systems for providing SSH, Telnet, and Rlogin protocol support.

CVE-2021-36367:PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response.

Affected Version:
PuTTY version prior to 0.76

QID Detection Logic
This QID checks the vulnerable version of PuTTY by checking the file version of file in registry and also checks in %programfiles%\PuTTY location.

Successful exploitation of this vulnerability may allow an attacker to capture credential data, and use that data for purposes that are undesired by the client user

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Customers are advised to upgrade to latest version PuTTY 0.76 Inorder to remediate this vulnerability.

    CVEs related to QID 375759

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-36367 URL Logo www.chiark.greenend.org.uk/~sgtatham/putty/changes.html