CVE-2020-24837
Last modified
CVE-2020-24837 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An integer underflow has been found in the latest version of ZCFees. The variables 'currPeriodIdx' and 'lastPeriodExecIdx' are both unsigned integers, and the result of the minus operation may be a negative integer which leads to an underflow. EPSS estimates a 1.57% chance of exploitation in the next 30 days.
Description
An integer underflow has been found in the latest version of ZCFees. The variables 'currPeriodIdx' and 'lastPeriodExecIdx' are both unsigned integers, and the result of the minus operation may be a negative integer which leads to an underflow. The attackers can modify the current timestamp of the transaction somehow and block the execution of the process function.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zcfees Project | Zcfees | All versions |
References
- https://etherscan.io/address/0x9d79c6e2a0222b9ac7bfabc447209c58fe9e0dcc#codePatch, Third Party Advisory
- https://etherscan.io/address/0x9d79c6e2a0222b9ac7bfabc447209c58fe9e0dcc#codePatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-24837?
How severe is CVE-2020-24837?
How do I fix CVE-2020-24837?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-24823A vulnerability in the dwarf::to_string function of Libelfin…5.5
- CVE-2020-24824A global buffer overflow issue in the dwarf::line_table::lin…5.5
- CVE-2020-24825A vulnerability in the line_table::line_table function of Li…5.5
- CVE-2020-24826A vulnerability in the elf::section::as_strtab function of L…5.5
- CVE-2020-24827A vulnerability in the dwarf::cursor::skip_form function of …5.5
- CVE-2020-24829An issue was discovered in GPAC from v0.5.2 to v0.8.0, as de…5.5
- CVE-2020-24838An integer overflow has been found in the the latest version…7.5
- CVE-2020-24841PNPSCADA 2.200816204020 allows SQL injection via parameter '…9.8
- CVE-2020-24842PNPSCADA 2.200816204020 allows cross-site scripting (XSS), w…6.1
- CVE-2020-24847A Cross-Site Request Forgery (CSRF) vulnerability is identif…4.3
- CVE-2020-24848FruityWifi through 2.4 has an unsafe Sudo configuration [(AL…7.8
- CVE-2020-24849A remote code execution vulnerability is identified in Fruit…8.8
Are you affected by CVE-2020-24837?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
