CVE-2017-15300
Last modified
CVE-2017-15300 is a vulnerability of currently unknown severity. The miner statistics HTTP API in EWBF Cuda Zcash Miner Version 0.3.4b hangs on incoming TCP connections until some sort of request is made (such as "GET / HTTP/1.1"), which allows for a Denial of Service attack preventing a user from viewing their mining statistics by an attacker opening a session with telnet or netcat and connecting to the miner on the HTTP API port.. EPSS estimates a 1.07% chance of exploitation in the next 30 days.
Description
The miner statistics HTTP API in EWBF Cuda Zcash Miner Version 0.3.4b hangs on incoming TCP connections until some sort of request is made (such as "GET / HTTP/1.1"), which allows for a Denial of Service attack preventing a user from viewing their mining statistics by an attacker opening a session with telnet or netcat and connecting to the miner on the HTTP API port.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ewbf | Cuda Zcash Miner | 0.3.4b |
References
- https://bitcointalk.org/index.php?topic=1707546.msg23016970#msg23016970Issue Tracking, Third Party Advisory
- https://www.legacysecuritygroup.com/cve-2017-15300.htmlThird Party Advisory
- https://bitcointalk.org/index.php?topic=1707546.msg23016970#msg23016970Issue Tracking, Third Party Advisory
- https://www.legacysecuritygroup.com/cve-2017-15300.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-15300?
How severe is CVE-2017-15300?
How do I fix CVE-2017-15300?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-15295Xpress Server in SAP POS does not require authentication for…
- CVE-2017-15296The Java component in SAP CRM has CSRF. This is SAP Security…
- CVE-2017-15297SAP Hostcontrol does not require authentication for the SOAP…
- CVE-2017-15298Git through 2.14.2 mishandles layers of tree objects, which …
- CVE-2017-15299The KEYS subsystem in the Linux kernel through 4.13.7 mishan…
- CVE-2017-1530IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable…
- CVE-2017-15302In CPUID CPU-Z through 1.81, there are improper access right…
- CVE-2017-15303In CPUID CPU-Z before 1.43, there is an arbitrary memory wri…
- CVE-2017-15304/bin/login.php in the Web Panel on the Airtame HDMI dongle w…
- CVE-2017-15305XSS exists in NexusPHP 1.5 via the keyword parameter to mess…
- CVE-2017-15306The kvm_vm_ioctl_check_extension function in arch/powerpc/kv…
- CVE-2017-15307Huawei Honor 8 smartphone with software versions earlier tha…
Are you affected by CVE-2017-15300?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
