VulnerabilityModified
CVE-2021-3006
The breed function in the smart contract implementation for Farm in Seal Finance (Seal), an Ethereum token, lacks access control and thus allows price manipulation, as exploited in the wild in December 2020 and January 2021.
HIGH 7.5EPSS 1.26%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.26%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The breed function in the smart contract implementation for Farm in Seal Finance (Seal), an Ethereum token, lacks access control and thus allows price manipulation, as exploited in the wild in December 2020 and January 2021.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.26% probability · 68th percentile
- CISA KEV
- Not listed
- Affected
- seal finance project/seal finance
- Source
- cve@mitre.org
References
- https://blocksecteam.medium.com/security-incident-on-seal-finance-fa79c27a1c3bExploit, Third Party Advisory
- https://etherscan.io/address/0x33c2da7fd5b125e629b3950f3c38d7f721d7b30dThird Party Advisory
- https://blocksecteam.medium.com/security-incident-on-seal-finance-fa79c27a1c3bExploit, Third Party Advisory
- https://etherscan.io/address/0x33c2da7fd5b125e629b3950f3c38d7f721d7b30dThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.