CVE-2024-32873 affects Evmos, the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network, specifically versions prior to 18.0.0. The vulnerability stems from an improper update of the spendable balance when delegating vested tokens, allowing a clawback vesting account to prematurely access unvested tokens. Rated as Medium severity (CVSS 4.3), it has a low impact on integrity (I:L) and requires low privileges (PR:L) for a network-based attack (AV:N). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.0.0CPE matchmatch criteria | cpe:2.3:a:evmos:evmos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.