Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-42806

Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, not signing and verifying `$\mathsf{cid}$` allows an attacker (which must be a participant of this head) to use a snapshot from an old head instance with the same participants to close the head or contest the state with it. This can lead to an incorrect distribution of value (= value extraction attack; hard, but possible) or prevent the head to finalize because the value available is not consistent with the closed utxo state (= denial of service; easy). A patch is planned for version 0.13.0. As a workaround, rotate keys between heads so not to re-use keys and not result in the same multi-signature participants.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 21.1%
CVSS Severity
CVSS v3 Score 6.5
References
Products affected by CVE-2023-42806
  • Iohk » Hydra » Version: N/A
    cpe:2.3:a:iohk:hydra:-
  • Iohk » Hydra » Version: 0.1.0
    cpe:2.3:a:iohk:hydra:0.1.0
  • Iohk » Hydra » Version: 0.10.0
    cpe:2.3:a:iohk:hydra:0.10.0
  • Iohk » Hydra » Version: 0.11.0
    cpe:2.3:a:iohk:hydra:0.11.0
  • Iohk » Hydra » Version: 0.12.0
    cpe:2.3:a:iohk:hydra:0.12.0
  • Iohk » Hydra » Version: 0.2.0
    cpe:2.3:a:iohk:hydra:0.2.0
  • Iohk » Hydra » Version: 0.3.0
    cpe:2.3:a:iohk:hydra:0.3.0
  • Iohk » Hydra » Version: 0.4.0
    cpe:2.3:a:iohk:hydra:0.4.0
  • Iohk » Hydra » Version: 0.5.0
    cpe:2.3:a:iohk:hydra:0.5.0
  • Iohk » Hydra » Version: 0.6.0
    cpe:2.3:a:iohk:hydra:0.6.0
  • Iohk » Hydra » Version: 0.7.0
    cpe:2.3:a:iohk:hydra:0.7.0
  • Iohk » Hydra » Version: 0.8.0
    cpe:2.3:a:iohk:hydra:0.8.0
  • Iohk » Hydra » Version: 0.8.1
    cpe:2.3:a:iohk:hydra:0.8.1
  • Iohk » Hydra » Version: 0.9.0
    cpe:2.3:a:iohk:hydra:0.9.0


Contact Us

Shodan ® - All rights reserved