CVE-2021-47759 MEDIUM

CVE-2021-47759: MTPutty 1.0.1.21 - SSH Password Disclosure

Vendor Ttyplus
Product MTPutty
Weakness CWE-522 · Insufficiently protected credentials
Published January 15, 2026
Last update January 15, 2026

CVSS base score

6.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

MTPutty 1.0.1.21 contains a sensitive information disclosure vulnerability that allows local attackers to view SSH connection passwords through Windows PowerShell process listing. Attackers can run a PowerShell command to retrieve the full command line of MTPutty processes, exposing plaintext SSH credentials.

Key dates

02Disclosure timeline

January 15, 2026 CVE published
January 15, 2026 Record updated