SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-26240

Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol.

HIGH 7.5EPSS 1.66%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. An ethash mining DAG generation flaw in Geth before version 1.9.24 could cause miners to erroneously calculate PoW in an upcoming epoch (estimated early January, 2021). This happened on the ETC chain on 2020-11-06. This issue is relevant only for miners, non-mining nodes are unaffected. This issue is fixed as of 1.9.24

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
1.66% probability · 75th percentile
CISA KEV
Not listed
Weakness
CWE-682
Affected
ethereum/go ethereum
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.