CVE-2021-3006
Last modified
CVE-2021-3006 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The breed function in the smart contract implementation for Farm in Seal Finance (Seal), an Ethereum token, lacks access control and thus allows price manipulation, as exploited in the wild in December 2020 and January 2021.. EPSS estimates a 1.26% chance of exploitation in the next 30 days.
Description
The breed function in the smart contract implementation for Farm in Seal Finance (Seal), an Ethereum token, lacks access control and thus allows price manipulation, as exploited in the wild in December 2020 and January 2021.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Seal Finance Project | Seal Finance | All versions |
References
- https://blocksecteam.medium.com/security-incident-on-seal-finance-fa79c27a1c3bExploit, Third Party Advisory
- https://etherscan.io/address/0x33c2da7fd5b125e629b3950f3c38d7f721d7b30dThird Party Advisory
- https://blocksecteam.medium.com/security-incident-on-seal-finance-fa79c27a1c3bExploit, Third Party Advisory
- https://etherscan.io/address/0x33c2da7fd5b125e629b3950f3c38d7f721d7b30dThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3006?
How severe is CVE-2021-3006?
How do I fix CVE-2021-3006?
Are you affected by CVE-2021-3006?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
