Insecure Password Storage in MobaXterm Affects Multiple Versions
CVE-2025-0714

6.5MEDIUM

Key Information:

Vendor

Mobatek

Status
Vendor
CVE Published:
17 February 2025

What is CVE-2025-0714?

The vulnerability in MobaXterm relates to insecure password storage, specifically in versions prior to 25.0. The application employs a static initialization vector (IV) generated through the encryption of null bytes using a derivative of the user's master key. This design flaw results in the same IV being reused for AES CFB encryption, making the encrypted data particularly susceptible to decryption. Consequently, sensitive information stored at rest may be easily compromised, posing a significant security risk.

Affected Version(s)

MobaXterm Windows 0 < 25.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

cirosec
.
CVE-2025-0714 : Insecure Password Storage in MobaXterm Affects Multiple Versions