Vulnerability CVE-2020-24838


Published: 2021-02-10

Description:
An integer overflow has been found in the the latest version of Issuer. The total issuedCount can be zero if the parameter is overly large. An attacker can obtain the private key of the owner issued with a certain 'amount', and the issuedCount can be zero if there is an overflow.

Type:

CWE-190

(Integer Overflow or Wraparound)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Issuer project -> Issuer 

 References:
https://etherscan.io/address/0xecaad8df0dee0b9ed45ffd1191b024701f21506c#code

Copyright 2024, cxsecurity.com

 

Back to Top