CVE-2022-38336

HIGH

MobaXterm < 22.2 - Unauthenticated SSH/SFTP Connection

Title source: llm
STIX 2.1

Description

An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without authentication.

References (1)

Core 1
Core References
Exploit, Mitigation, Third Party Advisory
https://docs.ssh-mitm.at/vulnerabilities/CVE-2022-38336.html

Scores

CVSS v3 8.1
EPSS 0.0083
EPSS Percentile 52.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
mobatek/mobaxterm < 22.2
Published Dec 06, 2022
Tracked Since Feb 18, 2026