Vulnerability Description
An integer underflow has been found in the latest version of ZCFees. The variables 'currPeriodIdx' and 'lastPeriodExecIdx' are both unsigned integers, and the result of the minus operation may be a negative integer which leads to an underflow. The attackers can modify the current timestamp of the transaction somehow and block the execution of the process function.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zcfees Project | Zcfees | - |
Related Weaknesses (CWE)
References
- https://etherscan.io/address/0x9d79c6e2a0222b9ac7bfabc447209c58fe9e0dcc#codePatchThird Party Advisory
- https://etherscan.io/address/0x9d79c6e2a0222b9ac7bfabc447209c58fe9e0dcc#codePatchThird Party Advisory
FAQ
What is CVE-2020-24837?
CVE-2020-24837 is a vulnerability with a CVSS score of 7.5 (HIGH). An integer underflow has been found in the latest version of ZCFees. The variables 'currPeriodIdx' and 'lastPeriodExecIdx' are both unsigned integers, and the result of the minus operation may be a ne...
How severe is CVE-2020-24837?
CVE-2020-24837 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-24837?
Check the references section above for vendor advisories and patch information. Affected products include: Zcfees Project Zcfees.