CVE-2017-15300
Dashboard / Vulnerabilities / CVE-2017-15300
CVE-2017-15300
Published: 15 Oct 2017Last Modified: 10 Mar 2026
Summary:
Details: The miner statistics HTTP API in EWBF Cuda Zcash Miner Version 0.3.4b hangs on incoming TCP connections until some sort of request is made (such as "GET / HTTP/1.1"), which allows for a Denial of Service attack preventing a user from viewing their mining statistics by an attacker opening a session with telnet or netcat and connecting to the miner on the HTTP API port.
References: , https://www.legacysecuritygroup.com/cve-2017-15300.html, https://bitcointalk.org/index.php?topic=1707546.msg23016970#msg23016970
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
