Description
The remote management interface on the Claymore Dual GPU miner 10.1 is vulnerable to an authenticated directory traversal vulnerability exploited by issuing a specially crafted request, allowing a remote attacker to read/write arbitrary files. This can be exploited via ../ sequences in the pathname to miner_file or miner_getfile.
In plain language
AI Worth attentionCVE-2017-16929 is a directory-traversal bug in the Claymore Dual GPU miner’s remote management interface that can let an attacker read or change files if they can log in; if you use this miner’s remote management, you should act now—no official fix is known.
Authenticated directory traversal in the Claymore Dual GPU miner 10.1 remote management interface (CWE-22/CWE-119) allows attackers to use specially crafted paths (e.g., ../ sequences) to read/write arbitrary files; public proof-of-concept exists and there’s no vendor patch information available.
What to do now
- Check whether you are running “Claymore Dual GPU miner 10.1” and whether its remote management interface is enabled.
- Verify whether the remote management port/interface is reachable from anywhere other than your trusted internal network (and not directly from the public internet).
- If remote management is needed, restrict access to known admin IPs/VPN only, and require strong, unique credentials for the interface.
- If you cannot restrict access reliably, shut off the remote management interface entirely and manage the miner locally.
- Look for any community-recommended workarounds or custom firewall rules that block traversal attempts on the management endpoint, since no official fixed version/patch is available.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
4 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-16929 and every CVE in our database. Create a free account — no credit card required.
Create Free Account