Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-31497

EPSS 21.97% · P96
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-31497

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. This is especially important in a scenario where an adversary is able to read messages signed by PuTTY or Pageant. The required set of signed messages may be publicly readable because they are stored in a public Git service that supports use of SSH for commit signing, and the signatures were made by Pageant through an agent-forwarding mechanism. In other words, an adversary may already have enough signature information to compromise a victim's private key, even if there is no further use of vulnerable PuTTY versions. After a key compromise, an adversary may be able to conduct supply-chain attacks on software maintained in Git. A second, independent scenario is that the adversary is an operator of an SSH server to which the victim authenticates (for remote login or file copy), even though this server is not fully trusted by the victim, and the victim uses the same private key for SSH connections to other services operated by other entities. Here, the rogue server operator (who would otherwise have no way to determine the victim's private key) can derive the victim's private key, and then use it for unauthorized access to those other services. If the other services include Git services, then again it may be possible to conduct supply-chain attacks on software maintained in Git. This also affects, for example, FileZilla before 3.67.0, WinSCP before 6.3.3, TortoiseGit before 2.15.0.1, and TortoiseSVN through 1.14.6.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
PuTTY 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
PuTTY是Simon Tatham个人开发者的一套免费的Telnet、Rlogin和SSH客户端软件。该软件主要用于对Linux系统进行远程管理。 PuTTY 0.68版本至0.80版本存在安全漏洞,该漏洞源于存在有偏差的随机数生成,允许攻击者通过快速攻击来恢复用户的NIST P-521密钥。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2024-31497

#POC DescriptionSource LinkShenlong Link
1 A script designed to uncover vulnerabilities in Putty by exploiting CVE-2024-31497.https://github.com/sh1k4ku/CVE-2024-31497POC Details
2Nonehttps://github.com/edutko/cve-2024-31497POC Details
3Proof Of Concept that exploits PuTTy CVE-2024-31497.https://github.com/HugoBond/CVE-2024-31497-POCPOC Details
4Nonehttps://github.com/LukaWynants/Onderzoek_CVE-2024-31497-POCPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-31497

登录查看更多情报信息。

Same Patch Batch · n/a · 2024-04-15 · 23 CVEs total

CVE-2024-30840Tenda AC15 安全漏洞
CVE-2024-30567JNT Telecom JNT Liftcom UMS 安全漏洞
CVE-2023-33806Hikvision Interactive Tablet DS-D5B86RB/B 安全漏洞
CVE-2020-22540Codoforum 安全漏洞
CVE-2020-22539Codoforum 安全漏洞
CVE-2024-31651Cosmetics and Beauty Product Online Store 安全漏洞
CVE-2024-30656Fireboltt Dream Wristphone 安全漏洞
CVE-2024-31652Cosmetics and Beauty Product Online Store 安全漏洞
CVE-2024-31650Cosmetics and Beauty Product Online Store 安全漏洞
CVE-2024-31649Cosmetics and Beauty Product Online Store 安全漏洞
CVE-2024-31648Insurance Management System 安全漏洞
CVE-2024-32488Foxit PDF Reader 安全漏洞
CVE-2023-45503Macrob7 Macs Framework Cms 安全漏洞
CVE-2024-28557SourceCodester Task Management System 安全漏洞
CVE-2024-28556SourceCodester Task Management System 安全漏洞
CVE-2024-28558Petrol Pump Management Software 安全漏洞
CVE-2024-24487Silex Technology DS-600 安全漏洞
CVE-2024-24486Silex Technology DS-600 安全漏洞
CVE-2024-24485Silex Technology DS-600 安全漏洞
CVE-2024-28056Amazon AWS Amplify 安全漏洞

Showing top 20 of 23 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2024-31497

No comments yet


Leave a comment