HIGH

CVE-2018-10058

CVSS v3

8.8

HIGH

EPSS Score

15.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the addpool, failover-only, poolquota, and save command handlers.

Technical details

Published
6/5/2018

Frequently asked questions

What is CVE-2018-10058?

The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the addpool, failover-only, poolquota, and save command handlers.

Is CVE-2018-10058 actively exploited?

Active exploitation of CVE-2018-10058 has not been confirmed. The EPSS score is 15.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-10058?

CVE-2018-10058 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2018-10058 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.