CVE-2023-35163 is a vulnerability in the Vega decentralized trading platform, affecting versions prior to 0.71.6, that allows a malicious validator to re-process past Ethereum events, leading to unauthorized credit of funds. The CVSS score of 5.2 (Medium) indicates a low attack complexity and no user interaction, but requires physical or local access to a validator key, which can be obtained for 3000 VEGA. While the vulnerability could result in significant financial manipulation, there are no known public exploits, Metasploit modules, or community discussions, and it is not listed in CISA's KEV catalog, suggesting a low current exploitation risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.71.6CPE matchmatch criteria | cpe:2.3:a:gobalsky:vega:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:C/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.