PT-2022-16782 · Goldshell · Goldshell Asic Miners

James A. Chambers

·

Published

2022-07-20

·

Updated

2022-07-27

·

CVE-2022-24660

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Goldshell ASIC Miners versions 2.2.1 and below
Description The debug interface of Goldshell ASIC Miners was discovered to be exposed publicly on the web interface, allowing attackers to access passwords and other sensitive information in plaintext.
Recommendations For Goldshell ASIC Miners versions 2.2.1 and below, update to a version above 2.2.1 to resolve the issue. As a temporary workaround, consider restricting access to the debug interface until a patch is available.

Exploit

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24660

Affected Products

Goldshell Asic Miners