CVE-2020-26264
LES Server DoS via GetProofsV2
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.25 a denial-of-service vulnerability can make a LES server crash via malicious GetProofsV2 request from a connected LES client. This vulnerability only concerns users explicitly enabling les server; disabling les prevents the exploit. The vulnerability was patched in version 1.9.25.
Go Ethereum, o "Geth", es la implementación oficial de Golang del protocolo Ethereum. En Geth versiones anteriores a 1.9.25, una vulnerabilidad de Denegación de Servicio puede hacer a un servidor LES bloquearse por medio de una petición GetProofsV2 maliciosa de un cliente LES conectado. Esta vulnerabilidad solo afecta a usuarios que habilitan explícitamente el servidor de archivos; deshabilitar archivos evita la explotación. La vulnerabilidad fue parcheada en versión 1.9.25
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-10-01 CVE Reserved
- 2020-12-11 CVE Published
- 2023-08-14 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/ethereum/go-ethereum/releases/tag/v1.9.25 | Third Party Advisory | |
https://github.com/ethereum/go-ethereum/security/advisories/GHSA-r33q-22hv-j29q | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/ethereum/go-ethereum/commit/bddd103a9f0af27ef533f04e06ea429cf76b6d46 | 2020-12-14 | |
https://github.com/ethereum/go-ethereum/pull/21896 | 2020-12-14 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ethereum Search vendor "Ethereum" | Go Ethereum Search vendor "Ethereum" for product "Go Ethereum" | < 1.9.25 Search vendor "Ethereum" for product "Go Ethereum" and version " < 1.9.25" | - |
Affected
|