Clawback Account Vulnerability Affects Evmos Ethereum Virtual Machine on Cosmos Network
CVE-2024-37158

8.1HIGH

Key Information:

Vendor

Evmos

Status
Vendor
CVE Published:
17 June 2024

What is CVE-2024-37158?

Evmos, serving as the Ethereum Virtual Machine hub within the Cosmos Network, has been found to contain a vulnerability that threatens the integrity of clawback vesting accounts. This flaw allows attackers to exploit differences in the ante handler checks for Ethereum and Cosmos transactions. Specifically, by sending an Ethereum transaction targeting a precompile used for interacting with a Cosmos SDK module, an attacker can bypass the necessary checks enforced by the Cosmos ante handler. The issue has been addressed in version 18.0.0, which effectively mitigates this vulnerability and enhances the security of transactions across both networks.

Affected Version(s)

evmos < 18.0.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.