Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-7690

Опубликовано: 13 мая 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 5
EPSS Низкий

Описание

In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of the process, even after the user disconnects from the remote SSH server. This affects Passwordless Authentication that has a Password Protected SSH Private Key.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mobatek:mobaxterm:11.1:3860:*:*:personal:*:*:*

EPSS

Процентиль: 63%
0.00456
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-255

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of the process, even after the user disconnects from the remote SSH server. This affects Passwordless Authentication that has a Password Protected SSH Private Key.

EPSS

Процентиль: 63%
0.00456
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-255