
Cloud Vulnerability DB
A community-led vulnerabilities database
Ethereum Solidity version 0.8.14 contains a vulnerability identified as CVE-2022-33069, which manifests as an assertion failure in the SMTEncoder::indexOrMemberAssignment() function at SMTEncoder.cpp. The vulnerability was discovered and disclosed in June 2022, affecting the Solidity compiler's SMTChecker component (NVD).
The vulnerability is characterized by an internal compiler error that occurs during the SMT (Satisfiability Modulo Theories) encoding process. Specifically, the issue triggers an assertion failure in the SMTEncoder::indexOrMemberAssignment() function located in the SMTEncoder.cpp file. The vulnerability has been assigned a CVSS v3.1 base score of 5.5 (Medium), with a vector string of CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H (NVD).
The vulnerability affects the availability of the Solidity compiler's SMTChecker component, potentially causing the compiler to crash during the compilation process of smart contracts. This can disrupt development workflows and contract verification processes (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."