Description
The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-6303 | The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected. |
References
History
Thu, 18 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Netapp
Subscribe
Active Iq Unified Manager
Subscribe
Aff A700s
Subscribe
Aff A700s Firmware
Subscribe
Hci Compute Node
Subscribe
Hci Management Node
Subscribe
Hci Storage Node
Subscribe
Ontap Select Deploy Administration Utility
Subscribe
Solidfire
Subscribe
Steelstore Cloud Integrated Storage
Subscribe
Openbsd
Subscribe
Openssh
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-18T14:41:37.776Z
Reserved: 2020-06-15T00:00:00.000Z
Link: CVE-2020-14145
Updated: 2024-08-04T12:39:36.101Z
Status : Modified
Published: 2020-06-29T18:15:11.940
Modified: 2025-12-18T15:15:48.410
Link: CVE-2020-14145
OpenCVE Enrichment
No data.
Weaknesses
EUVD