« Volver al listado

CVE-2024-58263

Estado: AnalizadaMedia (5.3)—

The cosmwasm-std crate before 2.0.2 for Rust allows integer overflows that cause incorrect contract calculations.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-58263",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-58263",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-28T15:25:27.835261Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@mitre.org",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "CosmWasm",
          "product": "cosmwasm-std",
          "versions": [
            {
              "status": "affected",
              "version": "1.3.0",
              "lessThan": "1.4.4",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.5.0",
              "lessThan": "1.5.4",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2.0.0",
              "lessThan": "2.0.2",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-07-27T20:15:25.230",
  "references": [
    {
      "url": "https://crates.io/crates/cosmwasm-std",
      "tags": [
        "Product"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/CosmWasm/advisories/blob/main/CWAs/CWA-2024-002.md",
      "tags": [
        "Exploit",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://rustsec.org/advisories/RUSTSEC-2024-0338.html",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@mitre.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-190"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The cosmwasm-std crate before 2.0.2 for Rust allows integer overflows that cause incorrect contract calculations."
    },
    {
      "lang": "es",
      "value": "El paquete cosmwasm-std para Rust anterior a 2.0.2 permite desbordamientos de enteros que causan cálculos de contrato incorrectos."
    }
  ],
  "lastModified": "2026-06-17T08:14:44.240",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cosmwasm:cosmwasm-std:*:*:*:*:*:rust:*:*",
              "vulnerable": true,
              "matchCriteriaId": "96E0ACB8-14BB-4D39-8025-BD7F4D8D433C",
              "versionEndExcluding": "1.4.4",
              "versionStartIncluding": "1.3.0"
            },
            {
              "criteria": "cpe:2.3:a:cosmwasm:cosmwasm-std:*:*:*:*:*:rust:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25C943FD-1794-44ED-94D0-4471C023C355",
              "versionEndExcluding": "1.5.4",
              "versionStartIncluding": "1.5.0"
            },
            {
              "criteria": "cpe:2.3:a:cosmwasm:cosmwasm-std:*:*:*:*:*:rust:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7384AFF-F099-4995-A2EB-540BD0D349D8",
              "versionEndExcluding": "2.0.2",
              "versionStartIncluding": "2.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}