PuTTY SSH Client Vulnerability Allows Private Key Recovery
ID: 7852a253-3cf6-518d-bb5c-f9ab4983fb81
STIX ID: report--7852a253-3cf6-518d-bb5c-f9ab4983fb81
Feed Name: Security Boulevard
Threat Score
**PuTTY ECDSA P-521 vulnerability (CVE-2024-31497)**: A flaw in the way PuTTY generated ECDSA P-521 signatures in versions 0.68–0.80 can allow attackers to recover private keys, risking unauthorized SSH access and impersonation; vendor patches (PuTTY 0.81 and updates for FileZilla, WinSCP, TortoiseGit) are available and all affected P-521 keys should be considered compromised and revoked.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
