QID 379099

Date Published: 2023-12-19

QID 379099: MobaTek MobaXterm Multiple Security Vulnerabilities

MobaXterm is an enhanced terminal for Windows with an X11 server, a tabbed SSH client and several other network tools for remote computing (VNC, RDP, telnet, rlogin). MobaXterm brings all the essential Unix commands to Windows desktop, in a single portable exe file which works out of the box.

CVE-2022-38337: When aborting a SFTP connection, MobaXterm before v22.2 sends a hardcoded password to the server. The server treats this as an invalid login attempt which can result in a Denial of Service (DoS) for the user if services like fail2ban are used.
CVE-2022-38336: An access control issue in MobaXterm before v22.2 allows attackers to make connections to the server via the SSH or SFTP protocols without authentication.

Affected Versions:
MobaTek MobaXterm before version 22.2

QID Detection Logic(Authenticated):
This checks for vulnerable version of MobaXtrem.exe file.

Successful exploitation of this Vulnerability allows attackers to make connections to the server via the SSH or SFTP protocols without authentication.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has issued a fix.
    For more information visit MobaXterm

    CVEs related to QID 379099

    Software Advisories
    Advisory ID Software Component Link
    MobaXterm URL Logo mobaxterm.mobatek.net/download-home-edition.html