PT-2022-11331 · Unknown · Antminer Monitor

Published

2022-06-17

·

Updated

2023-08-08

·

CVE-2021-40903

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Antminer Monitor version 0.50.0
Description A vulnerability exists in the Antminer Monitor due to a backdoor or misconfiguration inside a settings file in the flask server. The settings file contains a predefined secret string that is static, although it should be randomly generated.
Recommendations For Antminer Monitor version 0.50.0, consider regenerating the secret string to a random value to mitigate the risk of exploitation. As a temporary workaround, restrict access to the settings file in the flask server until a proper fix is applied.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2021-40903

Affected Products

Antminer Monitor