The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format string vulnerability, allowing remote attackers to read memory or cause a denial of service.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
https://medium.com/%40res1n/claymore-dual-gpu-miner-10-5-format-strings-vulnerability-916ab3d2db30 | |
https://www.exploit-db.com/exploits/43972/ | third party advisory vdb entry exploit |