Vulnerability Description
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner API. The flaw can be exploited only if the software is executed with read/write mode enabled.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nanopool | Claymore Dual Miner | <= 7.3 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/147678/Nanopool-Claymore-Dual-Miner-7.3-Rem
- http://packetstormsecurity.com/files/148578/Nanopool-Claymore-Dual-Miner-APIs-Re
- http://www.rapid7.com/db/modules/exploit/multi/misc/claymore_dual_miner_remote_m
- https://raw.githubusercontent.com/distributedweaknessfiling/cvelist/master/2018/
- https://reversebrain.github.io/2018/02/01/Claymore-Dual-Miner-Remote-Code-Execut
- https://reversebrain.github.io/2018/02/01/Claymore-Dual-Miner-Remote-Code-ExecutExploitThird Party Advisory
- https://twitter.com/ReverseBrain/status/951850534985662464Third Party Advisory
- https://www.exploit-db.com/exploits/44638/
- https://www.exploit-db.com/exploits/45044/
- http://packetstormsecurity.com/files/147678/Nanopool-Claymore-Dual-Miner-7.3-Rem
- http://packetstormsecurity.com/files/148578/Nanopool-Claymore-Dual-Miner-APIs-Re
- http://www.rapid7.com/db/modules/exploit/multi/misc/claymore_dual_miner_remote_m
- https://raw.githubusercontent.com/distributedweaknessfiling/cvelist/master/2018/
- https://reversebrain.github.io/2018/02/01/Claymore-Dual-Miner-Remote-Code-Execut
- https://reversebrain.github.io/2018/02/01/Claymore-Dual-Miner-Remote-Code-ExecutExploitThird Party Advisory
FAQ
What is CVE-2018-1000049?
CVE-2018-1000049 is a vulnerability with a CVSS score of 7.5 (HIGH). Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner API. The flaw can be exploited only if the software is executed with read/write...
How severe is CVE-2018-1000049?
CVE-2018-1000049 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1000049?
Check the references section above for vendor advisories and patch information. Affected products include: Nanopool Claymore Dual Miner.