Vulnerability Description
The _deposit function in the smart contract implementation for Stable Yield Credit (yCREDIT), an Ethereum token, has certain incorrect calculations. An attacker can obtain more yCREDIT tokens than they should.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Stableyieldcredit Project | Stableyieldcredit | - |
Related Weaknesses (CWE)
References
- https://blocksecteam.medium.com/deposit-less-get-more-ycredit-attack-details-f58ExploitThird Party Advisory
- https://etherscan.io/address/0xe0839f9b9688a77924208ad509e29952dc660261Third Party Advisory
- https://blocksecteam.medium.com/deposit-less-get-more-ycredit-attack-details-f58ExploitThird Party Advisory
- https://etherscan.io/address/0xe0839f9b9688a77924208ad509e29952dc660261Third Party Advisory
FAQ
What is CVE-2021-3004?
CVE-2021-3004 is a vulnerability with a CVSS score of 7.5 (HIGH). The _deposit function in the smart contract implementation for Stable Yield Credit (yCREDIT), an Ethereum token, has certain incorrect calculations. An attacker can obtain more yCREDIT tokens than the...
How severe is CVE-2021-3004?
CVE-2021-3004 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3004?
Check the references section above for vendor advisories and patch information. Affected products include: Stableyieldcredit Project Stableyieldcredit.