CVE-2022-36604

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
01/09/2022
Last modified:
08/09/2022

Description

An access control issue in Canaan Avalon ASIC Miner 2020.3.30 and below allows unauthenticated attackers to arbitrarily change user passwords via a crafted POST request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:canaan:avalon_asic_miner_firmware:*:*:*:*:*:*:*:* 2020.3.30 (including)
cpe:2.3:h:canaan:avalon_asic_miner:-:*:*:*:*:*:*:*