Incorrect calculation in yCREDIT - CVE-2021-3004

 

Incorrect calculation in yCREDIT - CVE-2021-3004

Published: January 3, 2021 / Updated: January 3, 2021


Vulnerability identifier: #VU49215
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3004
CWE-ID: CWE-682
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect calculation performed by the application. The _deposit function in the smart contract implementation for Stable Yield Credit (yCREDIT), an Ethereum token, has certain incorrect calculations. An attacker can obtain more yCREDIT tokens than they should.

Note, the vulnerability has been exploited in the wild in January 2021.


Affected software

yCREDIT

How to mitigate CVE-2021-3004

Install updates from vendor's website.


External References

Related Security Bulletins