Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-56513

Опубликовано: 30 сент. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An attacker capable of intercepting or redirecting traffic to the update url and can hijack the update process and deliver arbitrary executables that are automatically executed, resulting in full remote code execution. This constitutes a critical supply chain attack vector.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nicehash:quickminer:6.12.0:*:*:*:*:*:*:*

EPSS

Процентиль: 56%
0.00335
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 9.8
github
4 месяца назад

NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An attacker capable of intercepting or redirecting traffic to the update url and can hijack the update process and deliver arbitrary executables that are automatically executed, resulting in full remote code execution. This constitutes a critical supply chain attack vector.

EPSS

Процентиль: 56%
0.00335
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-494