CVE-2021-43839
CVSS V2 Medium 5
CVSS V3 High 7.5
Description
Cronos is a commercial implementation of a blockchain. In Cronos nodes running versions before v0.6.5, it is possible to take transaction fees from Cosmos SDK's FeeCollector for the current block by sending a custom crafted MsgEthereumTx. This problem has been patched in Cronos v0.6.5. There are no tested workarounds. All validator node operators are recommended to upgrade to Cronos v0.6.5 at their earliest possible convenience.
Overview
- CVE ID
- CVE-2021-43839
- Assigner
- security-advisories@github.com
- Vulnerability Status
- Analyzed
- Published Version
- 2021-12-21T17:15:08
- Last Modified Date
- 2022-01-05T15:10:00
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:crypto:cronos:*:*:*:*:*:*:*:* | 1 | OR | 0.6.5 | |
cpe:2.3:a:crypto:ethermint:*:*:*:*:*:*:*:* | 1 | OR | 0.7.3 | |
cpe:2.3:a:crypto:ethermint:*:*:*:*:*:*:*:* | 1 | OR | 0.8.0 | 0.9.0 |
cpe:2.3:a:crypto:evmos:*:*:*:*:*:*:*:* | 1 | OR | 0.4.2 |
CVSS Version 2
- Version
- 2.0
- Vector String
- AV:N/AC:L/Au:N/C:N/I:P/A:N
- Access Vector
- NETWORK
- Access Compatibility
- LOW
- Authentication
- NONE
- Confidentiality Impact
- NONE
- Integrity Impact
- PARTIAL
- Availability Impact
- NONE
- Base Score
- 5
- Severity
- MEDIUM
- Exploitability Score
- 10
- Impact Score
- 2.9
CVSS Version 3
- Version
- 3.1
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Attack Vector
- NETWORK
- Attack Compatibility
- LOW
- Privileges Required
- NONE
- User Interaction
- NONE
- Scope
- UNCHANGED
- Confidentiality Impact
- NONE
- Availability Impact
- NONE
- Base Score
- 7.5
- Base Severity
- HIGH
- Exploitability Score
- 3.9
- Impact Score
- 3.6
References
Reference URL | Reference Tags |
---|---|
https://github.com/crypto-org-chain/cronos/pull/270 | Patch Third Party Advisory |
https://github.com/crypto-org-chain/cronos/security/advisories/GHSA-f854-hpxv-cw9r | Third Party Advisory |
https://github.com/crypto-org-chain/cronos/commit/150ef237b37ac28c8136e1c0f494932860b9ebe8 | Patch Third Party Advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2021-43839 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43839 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2022-05-10 06:38:54 | Added to TrackCVE | |||
2022-12-06 04:29:07 | 2021-12-21T17:15Z | 2021-12-21T17:15:08 | CVE Published Date | updated |
2022-12-06 04:29:07 | 2022-01-05T15:10:00 | CVE Modified Date | updated | |
2022-12-06 04:29:07 | Analyzed | Vulnerability Status | updated |