← back
CVE-2021-36367highCWE-345

CVE-2021-36367

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.1epss 1.1%
exploitation probability
1.1%top 36% of all CVEs
observed exploitation
nono source reports it
In short

PuTTY allows SSH connections to proceed without proper authentication verification, making it easier for fake SSH servers to trick users into entering passwords that attackers can steal.

Technical detail

PuTTY fails to enforce authentication completion before session establishment, allowing an attacker-controlled SSH server to bypass authentication checks and subsequently present spoofed prompts to capture credentials. The vulnerability requires user interaction with a malicious server but enables credential interception for unauthorized use.

Summary generated and translated by AI from the official description.
PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user).
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Affected products
n/a · n/a