5
CVSSv2

CVE-2019-7690

Published: 13/05/2019 Updated: 15/05/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of the process, even after the user disconnects from the remote SSH server. This affects Passwordless Authentication that has a Password Protected SSH Private Key.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mobatek mobaxterm 11.1

Github Repositories

Source References for Published CVE & Advisory

Source References for Published CVE & Advisory [CVE-2019-7690] - Bleeding Process Memory through Dynamic Binary Instrumentation Framework Description: In MobaTek MobaXterm Personal Edition v111 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of the process, even after the user disconnects from the remote SSH se