vendor:
Antminer
by:
Corrado Liotta
8.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Antminer
Affected Version From: Antminer - D3, L3+, S9, and other
Affected Version To: Antminer - D3, L3+, S9, and other
Patch Exists: YES
Related CWE: CVE-2018-11220
CPE: a:bitmain:antminer
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows/Linux
2018
Bitmain Antminer D3, L3+, and S9 devices allow Remote Command Execution
The software used by the miners produced by the bitmain (AntMiner) is affected by a vulnerability of remote code execution type, it is possible through the 'Restore Backup' functionality of the administration portal to execute commands on the system. This would allow a malicious user with valid credentials to access the entire file system with administrative privileges.
Mitigation:
Ensure that the Antminer devices are configured with strong passwords and that the administrative portal is not accessible from the public internet.