KEVIntel
5.9
CVSS
Medium

CVE-2022-37450

PUBLISHED

Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of...

Exploited in the wild Remote No user interaction
Vendor
Ethereum
Product
Go Ethereum
Published
Aug 05, 2022
EPSS

Description

Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022.

CVSS scores

CVSS v3.1 5.9 Medium

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Exploitation status

Exploited in the wild

Recorded 2022-08-05 20:30:46 UTC · Source

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CVE Aug 05, 2022

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel