CVE-2019-6121: Nicehash Miner
Low severity, CVSS 3.7. EPSS: 1% chance of exploitation in the next 30 days.
An issue was discovered in NiceHash Miner before 2.0.3.0. Missing Authorization allows an adversary to can gain access to a miner's information about such as his recent payments, unclaimed Balance, Old Balance (at the time of December 2017 breach) , Projected payout, Mining stats like profitability, Efficiency, Number of workers, etc.. A valid Email address is required in order to retrieve this Information.
Affected products
- Nicehash Miner: before 2.0.3.0 (fixed in 2.0.3.0)
Published 2019-11-06. Last modified 2026-06-17.