PT-2019-17963 · Nicehash · Nicehash Miner

Ashutosh Barot

·

Published

2019-11-06

·

Updated

2020-08-24

·

CVE-2019-6120

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions NiceHash Miner versions prior to 2.0.3.0
Description A missing rate limit in the process of adding a wallet via email address allows remote attackers to submit a large number of email addresses, potentially identifying valid ones. This issue can be exploited in conjunction with a username enumeration technique to enumerate a large number of valid users' email addresses.
Recommendations For versions prior to 2.0.3.0, update to version 2.0.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the wallet addition feature via email address to minimize the risk of exploitation.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-6120

Affected Products

Nicehash Miner