Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wr4m-f8q9-97q2

Опубликовано: 30 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An attacker capable of intercepting or redirecting traffic to the update url and can hijack the update process and deliver arbitrary executables that are automatically executed, resulting in full remote code execution. This constitutes a critical supply chain attack vector.

NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An attacker capable of intercepting or redirecting traffic to the update url and can hijack the update process and deliver arbitrary executables that are automatically executed, resulting in full remote code execution. This constitutes a critical supply chain attack vector.

EPSS

Процентиль: 56%
0.00335
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 9.8
nvd
4 месяца назад

NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An attacker capable of intercepting or redirecting traffic to the update url and can hijack the update process and deliver arbitrary executables that are automatically executed, resulting in full remote code execution. This constitutes a critical supply chain attack vector.

EPSS

Процентиль: 56%
0.00335
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-494