LiveActive security incident?Get immediate response
CVE Record

CVE-2013-2292: bitcoind and Bitcoin-Qt 0.8.0 and earlier allow remote attackers to cause a denial of service (electricity...

bitcoind and Bitcoin-Qt 0.8.0 and earlier allow remote attackers to cause a denial of service (electricity consumption) by mining a block to create a nonstandard Bitcoin transaction containing multiple OP_CHECKSIG script opcodes.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This CVE describes a remote denial-of-service risk in bitcoind and Bitcoin-Qt 0.8.0 and earlier. An attacker could make affected nodes waste electricity and processing effort through specially structured Bitcoin transaction script behavior. The sources do not provide CVSS scoring or a named fixed version.

Executive priority

Treat this as a legacy-exposure cleanup item unless the organization still operates old Bitcoin node software. Business urgency rises if exposed nodes support financial operations, compliance evidence, mining, custody, or critical transaction workflows.

Technical view

The issue involves nonstandard Bitcoin transactions with multiple OP_CHECKSIG script opcodes inside a mined block. Affected bitcoind and Bitcoin-Qt 0.8.0 and earlier nodes could be forced into resource-consuming validation behavior. Source data lacks CWE mapping, CVSS details, and explicit remediation instructions.

Likely exposure

Exposure is most likely limited to organizations still running bitcoind or Bitcoin-Qt 0.8.0 or earlier, including old wallets, archival nodes, lab systems, or embedded operational scripts. The source bundle does not identify additional products or platforms.

Exploitation context

The bundle describes remote denial of service, but does not cite active exploitation. CISA KEV status is false. Exploitation would require affected Bitcoin node software and network conditions where the node processes the relevant blockchain data.

Researcher notes

Evidence is sparse: the CVE description identifies the vulnerable behavior and affected version range, but does not provide CVSS, CWE, fixed version, or detailed vendor mitigation. Do not expand affected scope beyond bitcoind and Bitcoin-Qt 0.8.0 and earlier without additional sources.

Mitigation direction

  • Inventory any bitcoind or Bitcoin-Qt deployments and identify versions.
  • Check upstream Bitcoin project guidance for corrected releases and migration notes.
  • Retire or isolate unsupported 0.8.0-era nodes from production operations.
  • Monitor affected systems for abnormal CPU, power, or validation workload.
  • Document any legacy-node business requirement and compensating controls.

Validation and detection

  • Confirm whether any node reports bitcoind or Bitcoin-Qt version 0.8.0 or earlier.
  • Review asset inventories, containers, startup scripts, and wallet hosts for legacy Bitcoin software.
  • Verify whether identified nodes accept peer-to-peer network traffic.
  • Check referenced Bitcoin CVE and discussion pages for vendor-confirmed remediation details.
  • Review monitoring history for unexplained sustained validation or power-consumption spikes.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2013-2292 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.