The miner statistics HTTP API in EWBF Cuda Zcash Miner Version 0.3.4b hangs on incoming TCP connections until some sort of request is made (such as "GET / HTTP/1.1"), which allows for a Denial of Service attack preventing a user from viewing their mining statistics by an attacker opening a session with telnet or netcat and connecting to the miner on the HTTP API port.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-10-15T08:00:00
Updated: 2024-08-05T19:50:16.492Z
Reserved: 2017-10-14T00:00:00
Link: CVE-2017-15300
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-10-15T08:29:00.200
Modified: 2024-11-21T03:14:25.103
Link: CVE-2017-15300
Redhat
No data.