Access Control Issue in MobaXterm Affects SSH and SFTP Protocols
CVE-2022-38336

8.1HIGH

Key Information:

Vendor

Mobatek

Status
Vendor
CVE Published:
6 December 2022

What is CVE-2022-38336?

An access control vulnerability has been identified in MobaXterm, permitting potential attackers to establish unauthenticated connections to servers utilizing SSH or SFTP protocols. This flaw compromises the integrity of secure communications, making it critical for users to upgrade to version 22.1 or later to safeguard against unauthorized access.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.