VYPR

Claymore Dual Miner

Sign in to watch

by Claymore Dual Miner Project

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-16930Cri0.719.80.54Dec 5, 2017The remote management interface on the Claymore Dual GPU miner 10.1 allows an unauthenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the request handler. This can be exploited via a long API request that is mishandled during logging.
CVE-2017-16929Hig0.588.10.27Dec 5, 2017The remote management interface on the Claymore Dual GPU miner 10.1 is vulnerable to an authenticated directory traversal vulnerability exploited by issuing a specially crafted request, allowing a remote attacker to read/write arbitrary files. This can be exploited via ../ sequences in the pathname to miner_file or miner_getfile.