DoS via maliciously crafted p2p message
CVE-2021-41173

5.7MEDIUM

Key Information:

Vendor

Ethereum

Vendor
CVE Published:
26 October 2021

What is CVE-2021-41173?

Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.9, a vulnerable node is susceptible to crash when processing a maliciously crafted message from a peer. Version v1.10.9 contains patches to the vulnerability. There are no known workarounds aside from upgrading.

Affected Version(s)

go-ethereum < 1.10.9

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-41173 : DoS via maliciously crafted p2p message