CVE-2015-6964

MEDIUM

MultiBit HD <0.1.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

MultiBit HD before 0.1.2 allows attackers to conduct bit-flipping attacks that insert unspendable Bitcoin addresses into the list that MultiBit uses to send fees to the developers. (Attackers cannot realistically steal these fees for themselves.) This occurs because there is no message authentication code (MAC).

Scores

CVSS v3 5.3
EPSS 0.0009
EPSS Percentile 25.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-697
Status published
Products (1)
multibit/multibit_hd < 0.1.2
Published Sep 25, 2023
Tracked Since Feb 18, 2026