Vulnerability Description
In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of the process, even after the user disconnects from the remote SSH server. This affects Passwordless Authentication that has a Password Protected SSH Private Key.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mobatek | Mobaxterm | 11.1 |
Related Weaknesses (CWE)
References
- https://github.com/yogeshshe1ke/CVE/blob/master/2019-7690/mobaxterm_exploit.pyExploitThird Party Advisory
- https://github.com/yogeshshe1ke/CVE/blob/master/2019-7690/mobaxterm_exploit.pyExploitThird Party Advisory
FAQ
What is CVE-2019-7690?
CVE-2019-7690 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of the process, even after the user disconnects from ...
How severe is CVE-2019-7690?
CVE-2019-7690 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-7690?
Check the references section above for vendor advisories and patch information. Affected products include: Mobatek Mobaxterm.