Vulnerability Description
The miner statistics HTTP API in EWBF Cuda Zcash Miner Version 0.3.4b hangs on incoming TCP connections until some sort of request is made (such as "GET / HTTP/1.1"), which allows for a Denial of Service attack preventing a user from viewing their mining statistics by an attacker opening a session with telnet or netcat and connecting to the miner on the HTTP API port.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ewbf | Cuda Zcash Miner | 0.3.4b |
References
- https://bitcointalk.org/index.php?topic=1707546.msg23016970#msg23016970Issue TrackingThird Party Advisory
- https://www.legacysecuritygroup.com/cve-2017-15300.htmlThird Party Advisory
- https://bitcointalk.org/index.php?topic=1707546.msg23016970#msg23016970Issue TrackingThird Party Advisory
- https://www.legacysecuritygroup.com/cve-2017-15300.htmlThird Party Advisory
FAQ
What is CVE-2017-15300?
CVE-2017-15300 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The miner statistics HTTP API in EWBF Cuda Zcash Miner Version 0.3.4b hangs on incoming TCP connections until some sort of request is made (such as "GET / HTTP/1.1"), which allows for a Denial of Serv...
How severe is CVE-2017-15300?
CVE-2017-15300 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15300?
Check the references section above for vendor advisories and patch information. Affected products include: Ewbf Cuda Zcash Miner.