Lucene search

K
redhatcveRedhat.comRH:CVE-2020-14145
HistoryJul 01, 2020 - 3:51 p.m.

CVE-2020-14145

2020-07-0115:51:38
redhat.com
access.redhat.com
268

0.003 Low

EPSS

Percentile

70.9%

A flaw was found in OpenSSH in versions 5.7 through 8.3, where an Observable Discrepancy occurs and leads to an information leak in the algorithm negotiation. This flaw allows a man-in-the-middle attacker to target initial connection attempts, where there is no host key for the server that has been cached by the client.

Mitigation

Always connect to SSH servers with verified host keys to avoid any possibilities of man-in-the-middle attack.