Vulnerability Description
RigoBlock Dragos through 2022-02-17 lacks the onlyOwner modifier for setMultipleAllowances. This enables token manipulation, as exploited in the wild in February 2022. NOTE: although 2022-02-17 is the vendor's vulnerability announcement date, the vulnerability will not be remediated until a major protocol upgrade occurs.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rigoblock | Drago | <= 2022-02-17 |
Related Weaknesses (CWE)
References
- https://etherscan.io/contractdiffchecker?a1=0x876b9ebd725d1fa0b879fcee12560a6453ProductThird Party Advisory
- https://etherscan.io/tx/0x5a6c108d5a729be2011cd47590583a04444d4e7c85cd0427071b96Third Party Advisory
- https://raw.globalsecuritydatabase.org/GSD-2022-1000077ExploitThird Party Advisory
- https://twitter.com/RigoBlock/status/1494351180713050116ExploitIssue TrackingThird Party Advisory
- https://twitter.com/danielvf/status/1494317265835147272ExploitIssue TrackingThird Party Advisory
- https://etherscan.io/contractdiffchecker?a1=0x876b9ebd725d1fa0b879fcee12560a6453ProductThird Party Advisory
- https://etherscan.io/tx/0x5a6c108d5a729be2011cd47590583a04444d4e7c85cd0427071b96Third Party Advisory
- https://raw.globalsecuritydatabase.org/GSD-2022-1000077ExploitThird Party Advisory
- https://twitter.com/RigoBlock/status/1494351180713050116ExploitIssue TrackingThird Party Advisory
- https://twitter.com/danielvf/status/1494317265835147272ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2022-25335?
CVE-2022-25335 is a vulnerability with a CVSS score of 7.5 (HIGH). RigoBlock Dragos through 2022-02-17 lacks the onlyOwner modifier for setMultipleAllowances. This enables token manipulation, as exploited in the wild in February 2022. NOTE: although 2022-02-17 is the...
How severe is CVE-2022-25335?
CVE-2022-25335 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-25335?
Check the references section above for vendor advisories and patch information. Affected products include: Rigoblock Drago.