CVE-2023-38698 is an integer overflow vulnerability in the Ethereum Name Service (ENS) @ensdomains/ens-contracts prior to version 0.0.22, allowing an attacker-controlled controller to reduce the expiration time of existing ENS domains. This medium-severity vulnerability (CVSS 6.5) could enable attackers to force domain expiration and claim them, with a low attack complexity and no user interaction required. While it currently requires a malicious DAO to exploit, future changes to ENS renewal policies or controller vulnerabilities could broaden its exploitability. There is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.0.22CPE matchmatch criteria | cpe:2.3:a:ens.domains:ethereum_name_service:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.