PT-2024-2774 · Winscp+6 · Winscp+7

Smartkeyss

·

Published

2024-03-05

·

Updated

2025-10-21

·

CVE-2024-31497

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PuTTY versions 0.68 through 0.80 FileZilla versions 3.24.1 through 3.66.5 WinSCP versions 5.9.5 through 6.3.2 TortoiseGit versions 2.4.0.2 through 2.15.0 TortoiseSVN versions 1.10.0 through 1.14.6
Description The issue is related to biased ECDSA nonce generation in PuTTY, allowing an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. This is especially important in scenarios where an adversary can read messages signed by PuTTY or Pageant, such as when messages are stored in a public Git service that supports SSH for commit signing. The vulnerability can be exploited to compromise private keys, potentially leading to unauthorized access to servers and services. In some cases, this could enable supply-chain attacks on software maintained in Git.
Recommendations For PuTTY versions 0.68 through 0.80, update to version 0.81 or later to fix the security issue. For FileZilla versions 3.24.1 through 3.66.5, update to version 3.67.0 or later. For WinSCP versions 5.9.5 through 6.3.2, update to version 6.3.3 or later. For TortoiseGit versions 2.4.0.2 through 2.15.0, update to version 2.15.0.1 or later. For TortoiseSVN versions 1.10.0 through 1.14.6, apply the available workaround or wait for a patch.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

ALSA-2024_1130
ALSA-2024_1150
ALSA-2025_16880
ALT-PU-2024-14430
ALT-PU-2024-15033
ALT-PU-2024-6830
ALT-PU-2024-9396
ALT-PU-2024-9607
ALT-PU-2024-9848
BDU:2024-02912
CVE-2024-31497
DLA-3839-1
GHSA-6P4C-R453-8743
MGASA-2024-0140
OPENSUSE-SU-2024:0111-1
OPENSUSE-SU-2024:13868-1
OPENSUSE-SU-2024:13870-1

Affected Products

Alt Linux
Debian
Filezilla
Putty
Red Os
Tortoisegit
Tortoisesvn
Winscp