Daily Dark Web
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
Daily Dark Web
No Result
View All Result
Home Vulnerability

PuTTY Vulnerability (CVE-2024-31497): Immediate Action Required for Private Key Protection

April 16, 2024
Reading Time: 2 mins read
PuTTY Vulnerability (CVE-2024-31497): Immediate Action Required for Private Key Protection

Security researchers Fabian Bäumer and Marcus Brinkmann from Ruhr University Bochum have identified a severe security flaw (CVE-2024-31497) in the popular SSH client PuTTY, affecting versions 0.68 to 0.80. This vulnerability extends to various software like FileZilla, WinSCP, TortoiseGit, and TortoiseSVN, compromising private keys used in the ECDSA algorithm with the NIST P-521 curve.


Vulnerability Details

The CVE-2024-31497 vulnerability stems from PuTTY’s flawed generation of random values (nonces) within the ECDSA signature process. In configurations with NIST P-251, the randomness is significantly biased, allowing attackers to reconstruct the private key with just around 60 compromised signatures.

Who’s Vulnerable
Users of PuTTY and related products relying on ECDSA NIST P-521 keys for SSH authentication are at risk. Attackers can acquire necessary signatures by briefly compromising SSH servers or from public sources where the key has been used, like signed Git commits.

Affected Tools
This vulnerability extends beyond PuTTY to impact several other tools, including FileZilla (Versions 3.24.1 – 3.66.5), WinSCP (Versions 5.9.5 – 6.3.2), TortoiseGit (Versions 2.4.0.2 – 2.15.0), and TortoiseSVN (Versions 1.10.0 – 1.14.6).

Consequences of Exploitation
Compromised private keys pose significant risks, allowing attackers to impersonate users and gain unauthorized access to servers. Even after patching, previously exposed keys remain permanently compromised, necessitating immediate action.

Recommended Actions

1- Identify Vulnerable Keys: Verify if you use ECDSA NIST P-521 keys, identifiable in PuTTYgen by fingerprints starting with “ecdsa-sha2-nistp521”.

2- Revoke Compromised Keys: Remove compromised public keys from authorized_keys files on servers and online services like GitHub to prevent unauthorized access.

3- Generate New Keys: Create fresh key pairs, preferably using Ed25519, to replace compromised ones and ensure secure authentication.

4- Update Software: Immediately update PuTTY to version 0.81 or later, along with FileZilla (version 3.67.0), WinSCP (version 6.3.3), TortoiseGit (version 2.15.0.1), and TortoiseSVN. For users unable to update TortoiseSVN, switch to using the updated PuTTY Plink for SSH connections.

Additional Information
The flaw does not expose signatures through passive network snooping; attackers require active control of a server or access to signed data.

While other ECDSA key sizes show slight bias, they are not practically exploitable at this time. Stay vigilant for further updates and advisories from security experts.

Tags: CVE-2024-31497ECDSANIST P-521PuTTYvulnerability
ShareTweet

Related Posts

CPUID Website Compromised: CPU-Z and HWMonitor Serve Malware
Vulnerability

CPUID Website Compromised: CPU-Z and HWMonitor Serve Malware

April 10, 2026
Axios npm Package Compromised in Supply Chain Attack
Vulnerability

Axios npm Package Compromised in Supply Chain Attack

March 31, 2026
Critical Figma MCP Server Flaw Allows Remote Code Execution
Vulnerability

Critical Figma MCP Server Flaw Allows Remote Code Execution

October 8, 2025
Oracle Patches CVE−2025−61882
Vulnerability

Oracle Patches CVE−2025−61882

October 6, 2025
Shai-Hulud Worm Infects Over 500 NPM Packages in Sophisticated Supply Chain Attack
Vulnerability

Shai-Hulud Worm Infects Over 500 NPM Packages in Sophisticated Supply Chain Attack

September 17, 2025
WinRAR Zero-Day RCE Vulnerability Allegedly for Sale for $65,000
Vulnerability

WinRAR Zero-Day RCE Vulnerability Allegedly for Sale for $65,000

September 8, 2025
Next Post
LulzSec Muslims ️Group Allegedly Hacked Efrat Airlines, Compromising Banking and Credit Card Information

LulzSec Muslims ️Group Allegedly Hacked Efrat Airlines, Compromising Banking and Credit Card Information

Sanggiero Allegedly Breaches Kameymall Database, Exposing Confidential User Data

Sanggiero Allegedly Breaches Kameymall Database, Exposing Confidential User Data

Recommended Stories

Everest Ransomware Group Allegedly Breaches UK Manufacturer EMM Corp – Exposing Over 900GB of Data

Everest Ransomware Group Allegedly Breaches UK Manufacturer EMM Corp – Exposing Over 900GB of Data

August 6, 2025
Court Decisions of Ukraine Database Breach Hits 44M Cases

Court Decisions of Ukraine Database Breach Hits 44M Cases

October 20, 2025
Threat Actor Claims to Leak Nokia Employee Data from Third Party Breach

Threat Actor Claims to Leak Nokia Employee Data from Third Party Breach

July 9, 2024

Popular Stories

  • SudamericaData Breach Exposes Over 1TB of Argentine Records

    SudamericaData Breach Exposes Over 1TB of Argentine Records

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    0 shares
    Share 0 Tweet 0
  • SUUMO, CHINTAI, At Home, HOME’S Suffer Data Breach

    0 shares
    Share 0 Tweet 0
  • Financial Tech Giant SilverLake Axis Allegedly Breached – 423GB of Data for Sale

    0 shares
    Share 0 Tweet 0
  • Telekom Serbia Investigates Leak of 160,000 Customer Records

    0 shares
    Share 0 Tweet 0
Daily Dark Web

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

No Result
View All Result
  • About Us
  • Home
  • Newsletter
  • Privacy Policy

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?