In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of the process, even after the user disconnects from the remote SSH server. This affects Passwordless Authentication that has a Password Protected SSH Private Key.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-05-13T15:58:33

Updated: 2019-05-13T16:00:12

Reserved: 2019-02-10T00:00:00


Link: CVE-2019-7690

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-05-13T16:29:01.383

Modified: 2019-05-15T14:46:43.893


Link: CVE-2019-7690

JSON object: View

cve-icon Redhat Information

No data.

CWE