MEDIUM · 5.9

CVE-2020-14145

The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connecti...

Vulnerability Description

The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected.

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
OpenbsdOpenssh>= 5.7, < 8.4
NetappAff A700S Firmware-
NetappAff A700S-
NetappActive Iq Unified Manager>= 9.5
NetappHci Management Node-
NetappOntap Select Deploy Administration Utility-
NetappSolidfire-
NetappSteelstore Cloud Integrated Storage-
NetappHci Compute Node-
NetappHci Storage Node-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-14145?

CVE-2020-14145 is a vulnerability with a CVSS score of 5.9 (MEDIUM). The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connecti...

How severe is CVE-2020-14145?

CVE-2020-14145 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-14145?

Check the references section above for vendor advisories and patch information. Affected products include: Openbsd Openssh, Netapp Aff A700S Firmware, Netapp Aff A700S, Netapp Active Iq Unified Manager, Netapp Hci Management Node.