CRITICAL · 9.8

CVE-2017-16930

The remote management interface on the Claymore Dual GPU miner 10.1 allows an unauthenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the request handler. Thi...

Vulnerability Description

The remote management interface on the Claymore Dual GPU miner 10.1 allows an unauthenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the request handler. This can be exploited via a long API request that is mishandled during logging.

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Claymore Dual Miner ProjectClaymore Dual Miner10.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-16930?

CVE-2017-16930 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The remote management interface on the Claymore Dual GPU miner 10.1 allows an unauthenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the request handler. Thi...

How severe is CVE-2017-16930?

CVE-2017-16930 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2017-16930?

Check the references section above for vendor advisories and patch information. Affected products include: Claymore Dual Miner Project Claymore Dual Miner.