PT-2018-9236 · Claymore · Nanopool Claymore Dual Miner

Reversebrain

·

Published

2018-02-09

·

Updated

2020-07-30

·

CVE-2018-1000049

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Nanopool Claymore Dual Miner versions prior to 7.3
Description: The issue allows for remote code execution by exploiting the miner API. This can only be done if the software is run with read/write mode enabled.
Recommendations: For versions prior to 7.3, consider disabling read/write mode to prevent exploitation until a fix is available. As a temporary workaround, restrict access to the miner API to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1000049

Affected Products

Nanopool Claymore Dual Miner