PT-2022-24375 · Mobaxterm · Mobaxterm

Manfred Kaiser

·

Published

2022-12-05

·

Updated

2023-02-03

·

CVE-2022-38337

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions MobaXterm versions prior to 22.1
Description The issue occurs when aborting a SFTP connection, where a hardcoded password is sent to the server. This can be treated as an invalid login attempt by the server, potentially leading to a Denial of Service (DoS) for the user if services like fail2ban are used.
Recommendations For versions prior to 22.1, update to version 22.1 or later to resolve the issue.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2022-38337

Affected Products

Mobaxterm