Incorrect calculation in yCREDIT - CVE-2021-3004

 

Incorrect calculation in yCREDIT - CVE-2021-3004

Published: January 3, 2021 / Updated: January 3, 2021


Vulnerability identifier: #VU49215
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:A/U:Amber
CVE-ID: CVE-2021-3004
CWE-ID: CWE-682
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild
Vendor: yCREDIT
Affected software:
yCREDIT

Detailed vulnerability description

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect calculation performed by the application. The _deposit function in the smart contract implementation for Stable Yield Credit (yCREDIT), an Ethereum token, has certain incorrect calculations. An attacker can obtain more yCREDIT tokens than they should.

Note, the vulnerability has been exploited in the wild in January 2021.


How to mitigate CVE-2021-3004

Install updates from vendor's website.

Sources