SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-32873

The issue allows a clawback vesting account to anticipate the release of unvested tokens.

MEDIUM 4.3EPSS 0.38%

Does this matter?

Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.

Description

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. The spendable balance is not updated properly when delegating vested tokens. The issue allows a clawback vesting account to anticipate the release of unvested tokens. This vulnerability is fixed in 18.0.0.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS
0.38% probability · 32th percentile
CISA KEV
Not listed
Weakness
CWE-682
Affected
evmos/evmos
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.