PT-2018-9272 · Cryptonote · Cryptonote

Ayrx

·

Publicado

2018-03-13

·

Atualizado

2018-04-05

·

CVE-2018-1000093

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: CryptoNote versions 0.8.9 and possibly later
Description: The issue allows for remote command execution and takeover of the cryptocurrency wallet. This can occur when an attacker tricks an application, such as a web browser, into connecting and sending a command to the local RPC server, which does not require authentication. The walletd and simplewallet RPC daemons will process any commands sent to them. An attack can be triggered by a victim visiting a webpage hosting malicious content.
Recommendations: For CryptoNote version 0.8.9 and possibly later, consider disabling the local RPC server or implementing authentication to prevent unauthorized access until a patch is available. Restrict access to the walletd and simplewallet RPC daemons to minimize the risk of exploitation. Avoid using the wallet on systems that can be tricked into connecting to malicious servers.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1000093

Produtos afetados

Cryptonote