Citrix warns admins to manually mitigate PuTTY SSH client bug
ID: 040af9f1-b372-55a8-8498-2a3e6d908d54
STIX ID: report--040af9f1-b372-55a8-8498-2a3e6d908d54
Feed Name: Bleeping Computer
Threat Score
Citrix warns that older XenCenter releases that bundle PuTTY are affected by CVE-2024-31497: a flaw in PuTTY versions prior to 0.81 causing weak ECDSA nonces for the NIST P-521 curve, which may allow a guest-VM attacker to recover an administrator's SSH private key; Citrix recommends replacing the bundled PuTTY with version 0.81 or later or removing the Open SSH Console functionality, and notes that newer XenCenter builds no longer include PuTTY.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
