CVE-2018-17144
high-risk
Published 2018-09-19
Bitcoin Core 0.14.x before 0.14.3, 0.15.x before 0.15.2, and 0.16.x before 0.16.3 and Bitcoin Knots 0.14.x through 0.16.x before 0.16.3 allow a remote denial of service (application crash) exploitable by miners via duplicate input. An attacker can make bitcoind or Bitcoin-Qt crash.
Do I need to act?
!
51.5% chance of exploitation in next 30 days
EPSS score — higher than 49% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (2)
Bitcoin Knots
Affected Vendors
References (10)
Vendor Advisory
https://bitcoincore.org/en/2018/09/18/release-0.16.3/
Third Party Advisory
https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures#CVE-2018-17144
Third Party Advisory
https://github.com/JinBean/CVE-Extension
Vendor Advisory
https://bitcoincore.org/en/2018/09/18/release-0.16.3/
Third Party Advisory
https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures#CVE-2018-17144
Third Party Advisory
https://github.com/JinBean/CVE-Extension
51
/ 100
high-risk
Severity
26/34 · High
Exploitability
18/34 · Moderate
Exposure
7/34 · Low