Back to search
CVE-2020-14145
Published: Jun 29, 2020
Modified: Dec 18, 2025
PUBLISHED
Description
The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://security.netapp.com/advisory/ntap-20200709-0004/
x_refsource_CONFIRM
[oss-security] 20201202 Some mitigation for openssh CVE-2020-14145
mailing-list
x_refsource_MLIST
https://docs.ssh-mitm.at/CVE-2020-14145.html
x_refsource_MISC
GLSA-202105-35
vendor-advisory
x_refsource_GENTOO
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now