Vulnerability Details CVE-2020-15091
TenderMint from version 0.33.0 and before version 0.33.6 allows block proposers to include signatures for the wrong block. This may happen naturally if you start a network, have it run for some time and restart it (**without changing chainID**). A malicious block proposer (even with a minimal amount of stake) can use this vulnerability to completely halt the network. This issue is fixed in Tendermint 0.33.6 which checks all the signatures are for the block with 2/3+ majority before creating a commit.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 36.9%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2020-15091
-
cpe:2.3:a:tendermint:tendermint:0.33.0
-
cpe:2.3:a:tendermint:tendermint:0.33.1
-
cpe:2.3:a:tendermint:tendermint:0.33.2
-
cpe:2.3:a:tendermint:tendermint:0.33.3