VDB
CVE-2018-20587
CVE-2018-20587
PUBLISHED
CVSS 5.5 MEDIUM
Bitcoin Core 0.12.0 through 0.17.1 and Bitcoin Knots 0.12.0 through 0.17.x before 0.17.1.knots20181229 have Incorrect Access Control. Local users can exploit this to steal currency by binding the RPC IPv4 localhost port, and forwarding requests to the IPv6 localhost port.
EPSS 0.35% · 28.0th percentile
Risk Scores
CVSS 3.0
5.5
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS Score
0.35%
28.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| bitcoinknots | bitcoin_knots | 0.12.0 |
| bitcoin | bitcoin_core | 0.12.0 |
| n/a | n/a | n/a |
Timeline
- Feb 11, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 1, 2022 EPSS Score
- May 3, 2022 EPSS Score
- May 13, 2022 CVE Updated
- Sep 6, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
References
- https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures#CVE-2018-20587 url
- https://medium.com/%40lukedashjr/cve-2018-20587-advisory-and-full-disclosure-a3105551e78b url
- https://nvd.nist.gov/vuln/detail/CVE-2018-20587 advisory
- https://medium.com/@lukedashjr/cve-2018-20587-advisory-and-full-disclosure-a3105551e78b url