CVE-2017-9230
CVE-2017-9230 Vulnerability Analysis & Exploit Intelligence
The Bitcoin Proof-of-Work algorithm does not consider a certain attack methodology related to 80-byte block headers with a variety of initial 64-byte chunks followed by the same 16-byte chunk, multiple candidate root values ending with the same 4 bytes, and calculations involving sqrt numbers. This violates the security assumptions of (1) the choice of input, outside of the dedicated nonce area, fed into the Proof-of-Work function should not change its difficulty to evaluate and (2) every Proof-of-Work function execution should be independent. NOTE: a number of persons feel that this methodology is a benign mining optimization, not a vulnerability
Published Updated Sources: cvelistV5, mitre
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Unreported
no source claims exploitation
EPSS
3%
chance of exploitation in 30 days
CVSS base
7.5
HIGH
CISA SSVC assessment
Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A stakeholder decision, not a severity score.
Exploitation
None
none · proof-of-concept · active
Automatable
Yes
can an attacker script all four kill-chain steps
Technical impact
Partial
partial · total control of the vulnerable component
Affected scope
The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.
Vendors (1)
Products (1)
Every base score collected
Sources score independently and disagree; each row says who scored it and under which version.
| Score | Version | Severity | Expl. | Impact | Source |
|---|---|---|---|---|---|
| 7.5 | CVSS 3.1 | HIGH | — | — | cvelistV5 |
Weakness & attack patterns
- CWE-338
References
7 on the record
- arxiv.org/ftp/arxiv/papers/1604/1604.00575.pdf
x_refsource_MISC
- lists.linuxfoundation.org/pipermail/bitcoin-dev/2017-April/013996.html
x_refsource_MISC
- lists.linuxfoundation.org/pipermail/bitcoin-dev/2017-May/014351.html
x_refsource_MISC
- www.securityfocus.com/bid/98657
vdb-entry, x_refsource_BID
- lists.linuxfoundation.org/pipermail/bitcoin-dev/2017-May/014352.html
x_refsource_MISC
- lists.linuxfoundation.org/pipermail/bitcoin-dev/2017-May/014349.html
x_refsource_MISC
- www.mit.edu/~jlrubin//public/pdfs/Asicboost.pdf
x_refsource_MISC
Elsewhere on this site
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.