CVE-2020-11014
CVE-2020-11014 — BIP LI01 output reordering may cause malformed SLP MINT transactions in Electron-Cash-SLP
Electron-Cash-SLP before version 3.6.2 has a vulnerability. All token creators that use the "Mint Tool" feature of the Electron Cash SLP Edition are at risk of sending the minting authority baton to the wrong SLP address. Sending the mint baton to the wrong address will give another party the ability to issue new tokens or permanently destroy future minting capability. This is fixed version 3.6.2.
Published Updated Sources: cvelistV5, GitHub_M
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Unreported
no source claims exploitation
EPSS
2%
chance of exploitation in 30 days
CVSS base
6.1
MEDIUM
Affected scope
The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.
Vendors (1)
Products (1)
Every base score collected
Sources score independently and disagree; each row says who scored it and under which version.
| Score | Version | Severity | Expl. | Impact | Source |
|---|---|---|---|---|---|
| 6.1 | CVSS 3.1 | MEDIUM | — | — | cvelistV5 |
References
4 on the record
- github.com/simpleledger/Electron-Cash-SLP/security/advisories/GHSA-cchm-grx2-g873
x_refsource_CONFIRM
- github.com/simpleledger/Electron-Cash-SLP/issues/126
x_refsource_MISC
- github.com/simpleledger/Electron-Cash-SLP/commit/ea3912c3d508ba81b280ef7d78648464f7f76fb8
x_refsource_MISC
- github.com/kristovatlas/rfc/blob/master/bips/bip-li01.mediawiki
x_refsource_MISC
Elsewhere on this site
- simpleledgerevery CVE for this vendor
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.