Email Enumeration Vulnerability in NiceHash Miner by NiceHash
CVE-2019-6120

7.5HIGH

Key Information:

Vendor

Nicehash

Status
Vendor
CVE Published:
6 November 2019

What is CVE-2019-6120?

A vulnerability in earlier versions of NiceHash Miner allows attackers to exploit a lack of rate limiting when adding wallet addresses via email. Attackers can submit numerous email addresses to identify valid ones. When combined with another vulnerability that supports username enumeration, an adversary can effectively compile a list of valid user email addresses, posing significant privacy risks to users and leading to potential phishing attacks.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-6120 : Email Enumeration Vulnerability in NiceHash Miner by NiceHash