Joined: Mar 15, 2021
Reaction score: 96
PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user).
CVSS Scores & Vulnerability Types
- Products Affected By CVE-2021-36367
- Number Of Affected Versions By Product
- References For CVE-2021-36367
- Metasploit Modules Related To CVE-2021-36367There are not any metasploit modules related