{"api_version":"1","generated_at":"2026-07-23T12:49:53+00:00","cve":"CVE-2022-24660","urls":{"html":"https://cve.report/CVE-2022-24660","api":"https://cve.report/api/cve/CVE-2022-24660.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-24660","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-24660"},"summary":{"title":"CVE-2022-24660","description":"The debug interface of Goldshell ASIC Miners v2.2.1 and below was discovered to be exposed publicly on the web interface, allowing attackers to access passwords and other sensitive information in plaintext.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2022-07-20 13:15:00","updated_at":"2022-07-27 22:03:00"},"problem_types":["CWE-312"],"metrics":[],"references":[{"url":"https://github.com/goldshellminer/firmware","name":"https://github.com/goldshellminer/firmware","refsource":"MISC","tags":[],"title":"GitHub - goldshellminer/firmware: goldshell miner firmware","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://jamesachambers.com/cryptocurrency-asic-miners-security-and-hacking-audit/","name":"https://jamesachambers.com/cryptocurrency-asic-miners-security-and-hacking-audit/","refsource":"MISC","tags":[],"title":"Cryptocurrency ASIC Miners - Security and Hacking Audit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-24660","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24660","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"24660","vulnerable":"1","versionEndIncluding":"2.2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"goldshell","cpe5":"goldshell_miner_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2022-24660","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The debug interface of Goldshell ASIC Miners v2.2.1 and below was discovered to be exposed publicly on the web interface, allowing attackers to access passwords and other sensitive information in plaintext."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/goldshellminer/firmware","refsource":"MISC","name":"https://github.com/goldshellminer/firmware"},{"refsource":"MISC","name":"https://jamesachambers.com/cryptocurrency-asic-miners-security-and-hacking-audit/","url":"https://jamesachambers.com/cryptocurrency-asic-miners-security-and-hacking-audit/"}]}},"nvd":{"publishedDate":"2022-07-20 13:15:00","lastModifiedDate":"2022-07-27 22:03:00","problem_types":["CWE-312"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:goldshell:goldshell_miner_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"2.2.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2022","CveId":"24660","Ordinal":"228010","Title":"CVE-2022-24660","CVE":"CVE-2022-24660","Year":"2022"},"notes":[{"CveYear":"2022","CveId":"24660","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}