Описание
The debug interface of Goldshell ASIC Miners v2.2.1 and below was discovered to be exposed publicly on the web interface, allowing attackers to access passwords and other sensitive information in plaintext.
Ссылки
- Third Party Advisory
- ExploitMitigationThird Party Advisory
- Third Party Advisory
- ExploitMitigationThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.2.1 (включая)
cpe:2.3:o:goldshell:goldshell_miner_firmware:*:*:*:*:*:*:*:*
EPSS
Процентиль: 19%
0.00061
Низкий
7.5 High
CVSS3
Дефекты
CWE-312
Связанные уязвимости
CVSS3: 7.5
github
почти 3 года назад
The debug interface of Goldshell ASIC Miners v2.2.1 and below was discovered to be exposed publicly on the web interface, allowing attackers to access passwords and other sensitive information in plaintext.
EPSS
Процентиль: 19%
0.00061
Низкий
7.5 High
CVSS3
Дефекты
CWE-312