Username Enumeration Vulnerability in NiceHash Miner by NiceHash
CVE-2019-6122

3.1LOW

Key Information:

Vendor

Nicehash

Status
Vendor
CVE Published:
6 November 2019

What is CVE-2019-6122?

A vulnerability exists in NiceHash Miner versions prior to 2.0.3.0 that allows attackers to exploit an error message to determine if a submitted email address is associated with an account. The application delivers an 'EMAIL DOES NOT EXIST' response for incorrect entries, while valid email addresses receive a different error message in the event of invalid credentials. This discrepancy can enable unauthorized users to confirm the existence of an account based on the error responses, potentially leading to targeted attacks.

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-6122 : Username Enumeration Vulnerability in NiceHash Miner by NiceHash