Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-35163

16
FAUCET Score

CVE-2023-35163 is a vulnerability in the Vega decentralized trading platform, affecting versions prior to 0.71.6, that allows a malicious validator to re-process past Ethereum events, leading to unauthorized credit of funds. The CVSS score of 5.2 (Medium) indicates a low attack complexity and no user interaction, but requires physical or local access to a validator key, which can be obtained for 3000 VEGA. While the vulnerability could result in significant financial manipulation, there are no known public exploits, Metasploit modules, or community discussions, and it is not listed in CISA's KEV catalog, suggesting a low current exploitation risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.71.6CPE matchmatch criteria
cpe:2.3:a:gobalsky:vega:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.0MEDIUM

CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:C/C:H/I:L/A:L

Attack Vector
PHYSICAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
0.2
Impact Score
5.3
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.49%
Probability of exploitation in next 30 days
EPSS Percentile
39.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0049 is in the 77th percentile among its peer group of 1,532 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: code.vegaprotocol.io/vegaFixed in: 0.71.6

Vendor Advisories (1)

goGHSA-8rc9-vxjh-qjf2medium

Vega's validators able to submit duplicate transactions

Jun 20, 2023

References

github.com / vegaprotocol/vega/commit/56b09bf57af8cd9eca5996252d86f469a3e34c68
Patch
github.com / vegaprotocol/vega/releases/tag/v0.71.6
Release Notes
github.com / vegaprotocol/vega/security/advisories/GHSA-8rc9-vxjh-qjf2
ExploitMitigationVendor Advisory