Claymore Dual Miner versions 10.5 and earlier contain an unauthenticated format string vulnerability in their remote management interface. This flaw allows remote attackers to supply format string specifiers, potentially enabling them to read arbitrary memory contents or crash the process, leading to denial of service.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is the official Metasploit Framework, a comprehensive and modular exploitation platform widely used for penetration testing, vulnerability research, and red teaming. The structure includes configuration files, Ruby application code, data files for exploits and payloads, and templates for auxiliary modules. The framework supports a vast array of attack vectors, including remote network exploitation, local privilege escalation, credential harvesting, and post-exploitation activities. It is highly extensible, allowing users to add new modules for exploits, payloads, auxiliary actions, and post-exploitation. The repository contains data files and templates for specific CVEs (e.g., CVE-2008-6508, CVE-2010-0842, CVE-2012-0013), configuration files for credential capture and email attacks, and a robust Ruby codebase for managing and executing exploits. As a weaponized exploitation framework, Metasploit provides both offensive and defensive security professionals with powerful tools for testing and demonstrating vulnerabilities across a wide range of platforms and services.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.