CVE-2020-14145 - CVE House
Back to Database
Status published Unknown CVE-2020-14145

The client side in OpenSSH 5.7 through 8.4 has an...

Vulnerability Description

The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-14145

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

openssh, aff a700s firmware, active iq unified manager, hci management node, ontap select deploy administration utility, solidfire, steelstore cloud integrated storage, hci compute node, hci storage node
Vulnerable Versions:
5.7, 8.4, 8.5, 8.6, 9.5

Timeline

Official Publish: June 29th, 2020
Last Modified: December 18th, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.