PT-2024-34628 · Unknown+1 · Watertoken Smart Contract+1

Published

2024-10-30

·

Updated

2024-11-04

·

CVE-2024-51425

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ethereum version 1.12.2 WaterToken smart contract (affected versions not specified)
Description An issue in the WaterToken smart contract, which can be run on the Ethereum blockchain, allows remote attackers to have an unspecified impact. The impact is disputed by third parties, who claim it is limited to function calls. This issue can be exploited to escalate privileges via the WaterToken Contract.
Recommendations For Ethereum version 1.12.2, consider restricting access to the WaterToken Contract to minimize the risk of exploitation. As a temporary workaround, consider disabling the WaterToken smart contract until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-51425

Affected Products

Ethereum
Watertoken Smart Contract