Mobatek kayıtları
mobatek üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-255 Credentials Management Errors1
- CWE-284 Improper Access Control1
- CWE-287 Improper Authentication1
- CWE-428 Unquoted Search Path or Element1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2017-15376İstismar yok | The TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute arbitrary commands vimobatek · mobaxterm · CWE-94 | Kritik9,8 | — | %3,8 | 16 Eki 2017 |
40Planlayın | CVE-2019-7690İstismar yok | In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the limobatek · mobaxterm · CWE-255 | Kritik9,8 | — | %3,2 | 13 May 2019 |
37İzleyin | CVE-2019-16305İstismar yok | In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection.mobatek · mobaxterm · CWE-77 | Yüksek8,8 | — | %6,7 | 14 Eyl 2019 |
36İzleyin | CVE-2019-13475İstismar yok | In MobaXterm 11.1, the mobaxterm: URI handler has an argument injection vulnerability that allows remote attackers to execute arbitrary commmobatek · mobaxterm · CWE-88 | Yüksek8,8 | — | %4,1 | 9 Tem 2019 |
36İzleyin | CVE-2022-38337İstismar yok | When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server.mobatek · mobaxterm · CWE-798 | Kritik9,1 | — | %0,8 | 5 Ara 2022 |
34İzleyin | CVE-2026-25866İstismar yok | MobaXterm < 26.1 Notepad++ Unquoted Service Pathmobatek · mobaxterm · CWE-428 | Yüksek8,5 | — | %0,2 | 9 Mar 2026 |
33İzleyin | CVE-2024-48200İstismar yok | An issue in MobaXterm v24.2 allows a local attacker to escalate privileges and execute arbitrary code via the remove function of the MobaXte | Yüksek8,4 | — | %0,2 | 31 Eki 2024 |
32İzleyin | CVE-2015-7244İstismar yok | The default configuration of the server in MobaXterm before 8.3 has a disabled Access Control setting and consequently does not require authmobatek · mobaxterm · CWE-284 | Yüksek7,5 | — | %5,0 | 3 Kas 2015 |
32İzleyin | CVE-2022-38336İstismar yok | An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without amobatek · mobaxterm · CWE-287 | Yüksek8,1 | — | %0,8 | 5 Ara 2022 |
30İzleyin | CVE-2021-28847İstismar yok | MobaXterm before 21.0 allows remote servers to cause a denial of service (Windows GUI hang) via tab title change requests that are sent repemobatek · mobaxterm | Yüksek7,5 | — | %1,4 | 3 Haz 2021 |
23İzleyin | CVE-2017-6805Kavram kanıtı | Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read arbitrary files via amobatek · mobaxterm · CWE-22 | Orta5,3 | — | %7,8 | 20 Mar 2017 |
- CVE-2017-1537640Planlayın
The TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute arbitrary commands vi
KritikCVSS 9,8İstismar yokEPSS %4mobatek · mobaxterm16 Eki 2017
- CVE-2019-769040Planlayın
In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the li
KritikCVSS 9,8İstismar yokEPSS %3mobatek · mobaxterm13 May 2019
- CVE-2019-1630537İzleyin
In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection.
YüksekCVSS 8,8İstismar yokEPSS %7mobatek · mobaxterm14 Eyl 2019
- CVE-2019-1347536İzleyin
In MobaXterm 11.1, the mobaxterm: URI handler has an argument injection vulnerability that allows remote attackers to execute arbitrary comm
YüksekCVSS 8,8İstismar yokEPSS %4mobatek · mobaxterm9 Tem 2019
- CVE-2022-3833736İzleyin
When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server.
KritikCVSS 9,1İstismar yokEPSS %1mobatek · mobaxterm5 Ara 2022
- CVE-2026-2586634İzleyin
MobaXterm < 26.1 Notepad++ Unquoted Service Path
YüksekCVSS 8,5İstismar yokEPSS %0mobatek · mobaxterm9 Mar 2026
- CVE-2024-4820033İzleyin
An issue in MobaXterm v24.2 allows a local attacker to escalate privileges and execute arbitrary code via the remove function of the MobaXte
YüksekCVSS 8,4İstismar yokEPSS %031 Eki 2024
- CVE-2015-724432İzleyin
The default configuration of the server in MobaXterm before 8.3 has a disabled Access Control setting and consequently does not require auth
YüksekCVSS 7,5İstismar yokEPSS %5mobatek · mobaxterm3 Kas 2015
- CVE-2022-3833632İzleyin
An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without a
YüksekCVSS 8,1İstismar yokEPSS %1mobatek · mobaxterm5 Ara 2022
- CVE-2021-2884730İzleyin
MobaXterm before 21.0 allows remote servers to cause a denial of service (Windows GUI hang) via tab title change requests that are sent repe
YüksekCVSS 7,5İstismar yokEPSS %1mobatek · mobaxterm3 Haz 2021
- CVE-2017-680523İzleyin
Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read arbitrary files via a
OrtaCVSS 5,3Kavram kanıtıEPSS %8mobatek · mobaxterm20 Mar 2017