Lucene search

K
cveMitreCVE-2016-8889
HistoryOct 28, 2016 - 3:59 p.m.

CVE-2016-8889

2016-10-2815:59:16
CWE-200
CWE-310
mitre
web.nvd.nist.gov
20
bitcoin
knots
vulnerability
cve-2016-8889
debug console
sensitive information
private keys
wallet passphrase
nvd

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

41.4%

In Bitcoin Knots v0.11.0.ljr20150711 through v0.13.0.knots20160814 (fixed in v0.13.1.knots20161027), the debug console stores sensitive information including private keys and the wallet passphrase in its persistent command history.

Affected configurations

Nvd
Node
bitcoin_knots_projectbitcoin_knotsMatch0.11.0
OR
bitcoin_knots_projectbitcoin_knotsMatch0.11.0rc1
OR
bitcoin_knots_projectbitcoin_knotsMatch0.11.0rc2
OR
bitcoin_knots_projectbitcoin_knotsMatch0.11.0rc3
OR
bitcoin_knots_projectbitcoin_knotsMatch0.11.1
OR
bitcoin_knots_projectbitcoin_knotsMatch0.11.1rc1
OR
bitcoin_knots_projectbitcoin_knotsMatch0.11.1rc2
OR
bitcoin_knots_projectbitcoin_knotsMatch0.11.2
OR
bitcoin_knots_projectbitcoin_knotsMatch0.11.2rc1
OR
bitcoin_knots_projectbitcoin_knotsMatch0.12.0
OR
bitcoin_knots_projectbitcoin_knotsMatch0.12.0rc1
OR
bitcoin_knots_projectbitcoin_knotsMatch0.12.0rc2
OR
bitcoin_knots_projectbitcoin_knotsMatch0.12.0rc3
OR
bitcoin_knots_projectbitcoin_knotsMatch0.12.0rc4
OR
bitcoin_knots_projectbitcoin_knotsMatch0.12.0rc5
OR
bitcoin_knots_projectbitcoin_knotsMatch0.12.0.knots20160226rc1
OR
bitcoin_knots_projectbitcoin_knotsMatch0.12.1.knots20160629rc2
OR
bitcoin_knots_projectbitcoin_knotsMatch0.13.0.knots20160814
VendorProductVersionCPE
bitcoin_knots_projectbitcoin_knots0.11.0cpe:2.3:a:bitcoin_knots_project:bitcoin_knots:0.11.0:*:*:*:*:*:*:*
bitcoin_knots_projectbitcoin_knots0.11.0cpe:2.3:a:bitcoin_knots_project:bitcoin_knots:0.11.0:rc1:*:*:*:*:*:*
bitcoin_knots_projectbitcoin_knots0.11.0cpe:2.3:a:bitcoin_knots_project:bitcoin_knots:0.11.0:rc2:*:*:*:*:*:*
bitcoin_knots_projectbitcoin_knots0.11.0cpe:2.3:a:bitcoin_knots_project:bitcoin_knots:0.11.0:rc3:*:*:*:*:*:*
bitcoin_knots_projectbitcoin_knots0.11.1cpe:2.3:a:bitcoin_knots_project:bitcoin_knots:0.11.1:*:*:*:*:*:*:*
bitcoin_knots_projectbitcoin_knots0.11.1cpe:2.3:a:bitcoin_knots_project:bitcoin_knots:0.11.1:rc1:*:*:*:*:*:*
bitcoin_knots_projectbitcoin_knots0.11.1cpe:2.3:a:bitcoin_knots_project:bitcoin_knots:0.11.1:rc2:*:*:*:*:*:*
bitcoin_knots_projectbitcoin_knots0.11.2cpe:2.3:a:bitcoin_knots_project:bitcoin_knots:0.11.2:*:*:*:*:*:*:*
bitcoin_knots_projectbitcoin_knots0.11.2cpe:2.3:a:bitcoin_knots_project:bitcoin_knots:0.11.2:rc1:*:*:*:*:*:*
bitcoin_knots_projectbitcoin_knots0.12.0cpe:2.3:a:bitcoin_knots_project:bitcoin_knots:0.12.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 181

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

41.4%

Related for CVE-2016-8889