漏洞描述
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner API. The flaw can be exploited only if the software is executed with read/write mode enabled.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
reversebrain.github.iohttps://reversebrain.github.io/2018/02/01/Claymore-Dual-Miner-Remote-Code-Execution↗raw.githubusercontent.comhttps://raw.githubusercontent.com/distributedweaknessfiling/cvelist/master/2018/1000xxx/CVE-2018-1000049.json↗twitter.comhttps://twitter.com/ReverseBrain/status/951850534985662464↗packetstormsecurity.comhttp://packetstormsecurity.com/files/148578/Nanopool-Claymore-Dual-Miner-APIs-Remote-Code-Execution.html↗packetstormsecurity.comhttp://packetstormsecurity.com/files/147678/Nanopool-Claymore-Dual-Miner-7.3-Remote-Code-Execution.html↗reversebrain.github.iohttps://reversebrain.github.io/2018/02/01/Claymore-Dual-Miner-Remote-Code-Execution/↗