PT-2015-7490 · Mobatek · Mobaxterm

Bryan Rhodes

+3

·

Publicado

2015-11-04

·

Atualizado

2015-11-04

·

CVE-2015-7244

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MobaXterm versions prior to 8.3
Description The default configuration of the server in MobaXterm has a disabled Access Control setting, which does not require authentication for X11 connections. This allows remote attackers to execute arbitrary commands or obtain sensitive information via X11 packets.
Recommendations For versions prior to 8.3, enable the Access Control setting to require authentication for X11 connections.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-7244

Produtos afetados

Mobaxterm