CVE-2020-14002: Fedoraproject Fedora
Medium severity, CVSS 5.9. EPSS: 3.1% chance of exploitation in the next 30 days.
PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client).
Affected products
- Fedoraproject Fedora: version 31 only; version 32 only
- Netapp Oncommand Unified Manager Core Package: affected versions not specified
- Putty Putty: from 0.68, up to and including 0.73
Published 2020-06-29. Last modified 2026-06-17.