vendor:
MTPutty
by:
Sedat Ozdemir
7.5
CVSS
HIGH
Password Disclosure
200
CWE
Product Name: MTPutty
Affected Version From: 1.0.1.21
Affected Version To: 1.0.1.21
Patch Exists: YES
Related CWE:
CPE: a:ttyplus:mtputty:1.0.1.21
Platforms Tested: Windows 10
2021
MTPutty 1.0.1.21 – SSH Password Disclosure
MTPutty is vulnerable to a password disclosure vulnerability. By running the command “Get-WmiObject Win32_Process | select name, commandline | findstr putty.exe” on powershell, an attacker can view the hidden password.
Mitigation:
Users should update to the latest version of MTPutty and use strong passwords.