PT-2019-18704 · Mobaxterm · Mobaxterm Personal Edition

Y0Gesh_She1Ke

+1

·

Publicado

2019-05-13

·

Atualizado

2019-05-15

·

CVE-2019-7690

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MobaXterm Personal Edition version 11.1 Build 3860
Description The issue allows retrieval of the SSH private key and its password from process memory for the lifetime of the process, even after disconnection from the remote SSH server. This affects passwordless authentication with a password-protected SSH private key.
Recommendations For MobaXterm Personal Edition version 11.1 Build 3860, consider disabling passwordless authentication that uses a password-protected SSH private key until a fix is available. Restrict access to sensitive information and limit the use of SSH private keys to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-7690

Produtos afetados

Mobaxterm Personal Edition