HIGH SEVERITY

CVE-2017-9230

Bitcoin vulnerability

CVSS
7.5
EPSS
3.3%
EPSS pct
87th
Exploited
No known
The Bitcoin Proof-of-Work algorithm does not consider a certain attack methodology related to 80-byte block headers with a variety of initial 64-byte chunks followed by the same 16-byte chunk, multiple candidate root values ending with the same 4 bytes, and calculations involving sqrt numbers. This violates the security assumptions of (1) the choice of input, outside of the dedicated nonce area, fed into the Proof-of-Work function should not change its difficulty to evaluate and (2) every Proof-of-Work function execution should be independent. NOTE: a number of persons feel that this methodology is a benign mining optimization, not a vulnerability
Affected vendor
Bitcoin
Affected product
Bitcoin
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness type (CWE)
  • CWE-338 — Use of Cryptographically Weak PRNG
Published
2017-05-24

Risk analysis

Based on its CVSS vector, this vulnerability is exploitable over the network, low attack complexity, requiring no privileges, no user interaction. Successful exploitation leads to high impact to confidentiality.

Its EPSS score of 3.3% reflects a lower probability of exploitation activity in the wild over the next 30 days, placing it above 87% of all scored CVEs.

Check your external exposure to CVE-2017-9230

  • Confirm whether Bitcoin Bitcoin is running on any internet-facing host or subdomain.
  • Match discovered service fingerprints against the version affected by CVE-2017-9230.
  • Prioritise remediation if the asset is public, business-critical, or near authentication/payment flows.

How ThreatPort helps with CVE-2017-9230

ThreatPort's external attack surface scanner checks your internet-facing assets — agentlessly, from the outside in — for the exposed services and versions that CVE-2017-9230 affects, then prioritises the finding by real risk using CISA KEV and FIRST.org EPSS.

Run a free external exposure scan

Are you exposed to CVE-2017-9230?

Run an instant, non-intrusive external scan to check your attack surface for CVE-2017-9230.

Start free scan

No credit card. Agentless.