CVE-2018-1000093
CryptoNote version version 0.8.9 and possibly later contain a local RPC server which does not require authentication, as a result the walletd and the simplewallet RPC daemons will process any commands sent to them, resulting in remote command execution…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
CryptoNote version version 0.8.9 and possibly later contain a local RPC server which does not require authentication, as a result the walletd and the simplewallet RPC daemons will process any commands sent to them, resulting in remote command execution and a takeover of the cryptocurrency wallet if an attacker can trick an application such as a web browser into connecting and sending a command for example. This attack appears to be exploitable via a victim visiting a webpage hosting malicious content that trigger such behavior.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 1.71% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- cryptonote/cryptonote
- Source
- cve@mitre.org
References
- https://github.com/amjuarez/bytecoin/issues/217Broken Link, Third Party Advisory
- https://github.com/cryptonotefoundation/cryptonote/issues/172Exploit, Issue Tracking, Third Party Advisory
- https://www.ayrx.me/cryptonote-unauthenticated-json-rpcExploit, Third Party Advisory
- https://github.com/amjuarez/bytecoin/issues/217Broken Link, Third Party Advisory
- https://github.com/cryptonotefoundation/cryptonote/issues/172Exploit, Issue Tracking, Third Party Advisory
- https://www.ayrx.me/cryptonote-unauthenticated-json-rpcExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.