9.8
CVE-2022-24657
- EPSS 0.4%
- Veröffentlicht 20.07.2022 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:50:48
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Goldshell ASIC Miners v2.1.x was discovered to contain hardcoded credentials which allow attackers to remotely connect via the SSH protocol (port 22).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Goldshell ≫ Goldshell Miner Firmware Version >= 2.0.0 <= 2.2.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.6 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.