CVE-2019-7690
Last modified
CVE-2019-7690 is a vulnerability of currently unknown severity. In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of the process, even after the user disconnects from the remote SSH server. This affects Passwordless Authentication that has a Password Protected SSH Private Key.. EPSS estimates a 3.21% chance of exploitation in the next 30 days.
Description
In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of the process, even after the user disconnects from the remote SSH server. This affects Passwordless Authentication that has a Password Protected SSH Private Key.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Mobatek | Mobaxterm | 11.1 | 3860 |
References
- https://github.com/yogeshshe1ke/CVE/blob/master/2019-7690/mobaxterm_exploit.pyExploit, Third Party Advisory
- https://github.com/yogeshshe1ke/CVE/blob/master/2019-7690/mobaxterm_exploit.pyExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-7690?
How severe is CVE-2019-7690?
How do I fix CVE-2019-7690?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-7675An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices.…
- CVE-2019-7676A weak password vulnerability was discovered in Enphase Envo…
- CVE-2019-7677XSS exists in Enphase Envoy R3.*.* via the profileName param…
- CVE-2019-7678A directory traversal vulnerability was discovered in Enphas…
- CVE-2019-7684inxedu through 2018-12-24 has a vulnerability that can lead …
- CVE-2019-7687cgi-bin/qcmap_web_cgi on JioFi 4 jmr1140 Amtel_JMR1140_R12.0…
- CVE-2019-7692install/install.php in CIM 0.9.3 allows remote attackers to …
- CVE-2019-7693Axios Italia Axios RE 1.7.0/7.0.0 devices have XSS via the R…
- CVE-2019-7697An issue was discovered in Bento4 v1.5.1-627. There is an as…
- CVE-2019-7698An issue was discovered in AP4_Array<AP4_CttsTableEntry>::En…
- CVE-2019-7699A heap-based buffer over-read occurs in AP4_BitStream::Write…
- CVE-2019-7700A heap-based buffer over-read was discovered in wasm::WasmBi…6.5
Are you affected by CVE-2019-7690?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
