CVE-2021-42764 describes a critical denial-of-service vulnerability affecting the Proof-of-Stake (PoS) Ethereum consensus protocol. An unauthenticated attacker can exploit this flaw through short-range reorganizations of the blockchain, leading to delayed consensus decisions and increased profits for individual validators. With a CVSS score of 9.1 (CRITICAL), this vulnerability has a high impact on availability and integrity, requiring no user interaction or special privileges to exploit. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there is minimal community discussion or media coverage, its critical severity warrants attention. It is not listed in CISA's Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2021-10-19CPE matchmatch criteria | cpe:2.3:a:proof-of-stake_ethereum_project:proof-of-stake_ethereum:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.