CVE-2024-39696
vulnerability analysis and mitigation

Overview

CVE-2024-39696 affects Evmos, a decentralized Ethereum Virtual Machine chain on the Cosmos Network. The vulnerability was discovered in versions prior to 19.0.0, where users could create a vesting account with a third-party account as funder and exploit an authorization check flaw. The issue was disclosed on July 5, 2024, and patched in version 19.0.0 (Vendor Advisory).

Technical details

The vulnerability stems from an improper authorization check in the fundVestingAccount function. A user could create a vesting account designating a third-party account (either an Externally Owned Account or contract) as the funder. While the code checks authorization for the contract.CallerAddress, the actual funds are taken from the funder address specified in the message. This implementation flaw allows unauthorized fund transfers from any address on the chain (Security Online, Vendor Advisory).

Impact

The vulnerability was classified as Critical according to the ImmuneFi Severity Classification System. It could potentially be exploited to drain funds from any account on the Evmos blockchain, leading to a total loss of funds across the entire chain (Security Online).

Mitigation and workarounds

The vulnerability has been patched in Evmos version 19.0.0. Users and organizations running affected versions should upgrade immediately to the patched version to prevent potential exploitation (Vendor Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
David EstlickCISO
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
Adam FletcherChief Security Officer
“We know that if Wiz identifies something as critical, it actually is.”
Greg PoniatowskiHead of Threat and Vulnerability Management