The default configuration of the server in MobaXterm before 8.3 has a disabled Access Control setting and consequently does not require authentication for X11 connections, which allows remote attackers to execute arbitrary commands or obtain sensitive information via X11 packets.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: certcc
Published: 2015-11-04T02:00:00
Updated: 2024-08-06T07:43:45.692Z
Reserved: 2015-09-18T00:00:00
Link: CVE-2015-7244
Vulnrichment
No data.
NVD
Status : Modified
Published: 2015-11-04T03:59:12.950
Modified: 2024-11-21T02:36:25.460
Link: CVE-2015-7244
Redhat
No data.