CVE-2024-37158
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Preliminary checks on actions computed by the clawback vesting accounts are performed in the ante handler. Evmos core, implements two different ante handlers: one for Cosmos transactions and one for Ethereum transactions. Checks performed on the two implementation are different. The vulnerability discovered allowed a clawback account to bypass Cosmos ante handler checks by sending an Ethereum transaction targeting a precompile used to interact with a Cosmos SDK module. This vulnerability is fixed in 18.0.0.
Scoring
- Severity
- LOW
- CVSS base score
- 3.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
- EPSS probability
- 0.44%
- CWE
- CWE-691
- Published
- 2024-06-17
- Last modified
- 2026-03-13
Affected products
- evmos evmos
Weakness type
Related vulnerabilities
- CVE-2026-20276 — Cisco IOS XR Software Security Hardening Release: September 2026
- CVE-2026-79033 — Insufficient control flow management in DevTools in Google Chrome prior to 152.0.7977.65 allowed a...
- CVE-2026-20271 — Cisco IOS XE Software Security Hardening Release
- CVE-2026-5938 — Foxit PDF Editor/Reader Infinite Loop Denial-of-Service Vulnerability
- CVE-2025-35963 — Insufficient control flow management for some Intel(R) PROSet/Wireless WiFi Software for Windows...
- CVE-2025-25273 — Insufficient control flow management in the Linux kernel-mode driver for some Intel(R) 700 Series...
- CVE-2025-24305 — Insufficient control flow management in the Alias Checking Trusted Module (ACTM) firmware for some...
- CVE-2025-22893 — Insufficient control flow management in the Linux kernel-mode driver for some Intel(R) 800 Series...