CVE-2018-6317
CRITICALClaymore Dual Miner < 10.5 - Unauthenticated Format String Vulnerability
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-6317. PoCs published by res1n.
AI-analyzed exploit summary The exploit demonstrates a format string vulnerability in Claymore’s Dual GPU Miner 10.5 and below, allowing unauthenticated attackers to read memory addresses or cause a denial of service by sending malformed JSON-RPC requests to port 3333. The PoC includes commands to trigger the vulnerability using format specifiers like %s, %p, and %n.
Description
The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format string vulnerability, allowing remote attackers to read memory or cause a denial of service.
Exploits (1)
The exploit demonstrates a format string vulnerability in Claymore’s Dual GPU Miner 10.5 and below, allowing unauthenticated attackers to read memory addresses or cause a denial of service by sending malformed JSON-RPC requests to port 3333. The PoC includes commands to trigger the vulnerability using format specifiers like %s, %p, and %n.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H