// For flags

CVE-2022-21685

Integer underflow in Frontier

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Frontier is Substrate's Ethereum compatibility layer. Prior to commit number `8a93fdc6c9f4eb1d2f2a11b7ff1d12d70bf5a664`, a bug in Frontier's MODEXP precompile implementation can cause an integer underflow in certain conditions. This will cause a node crash for debug builds. For release builds (and production WebAssembly binaries), the impact is limited as it can only cause a normal EVM out-of-gas. Users who do not use MODEXP precompile in their runtime are not impacted. A patch is available in pull request #549.

Frontier es la capa de compatibilidad con Ethereum de Substrate. Antes del número de commit "8a93fdc6c9f4eb1d2f2a11b7ff1d12d70bf5a664", un error en la implementación de precompilación MODEXP de Frontier puede causar un desbordamiento de enteros en determinadas condiciones. Esto causará un bloqueo del nodo en las versiones de depuración. Para las compilaciones de lanzamiento (y los binarios WebAssembly de producción), el impacto es limitado, ya que sólo puede causar un desbordamiento normal de EVM. Los usuarios que no usan la precompilación MODEXP en su tiempo de ejecución no están afectados. Un parche está disponible en el pull request #549

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-11-16 CVE Reserved
  • 2022-01-14 CVE Published
  • 2023-09-05 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-191: Integer Underflow (Wrap or Wraparound)
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Parity
Search vendor "Parity"
Frontier
Search vendor "Parity" for product "Frontier"
<= 2022-01-13
Search vendor "Parity" for product "Frontier" and version " <= 2022-01-13"
-
Affected