CVE-2023-41052
LOWDescription
Vyper is a Pythonic Smart Contract Language. In affected versions the order of evaluation of the arguments of the builtin functions `uint256_addmod`, `uint256_mulmod`, `ecadd` and `ecmul` does not follow source order. This behaviour is problematic when the evaluation of one of the arguments produces side effects that other arguments depend on. A patch is currently being developed on pull request #3583. When using builtins from the list above, users should make sure that the arguments of the expression do not produce side effects or, if one does, that no other argument is dependent on those side effects.
How to fix
No published remediation has been found for this vulnerability's affected products yet.
Mitigation guidance may be in the linked vendor advisories in the References section below.
TridentStack Control tracks known vulnerabilities across your Windows, macOS, and Linux fleet and shows the fix as soon as one is published. See how it works
CVSS v3 Vector
Exploitability
Impact
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploit Intelligence
Low risk: more likely to be exploited than 37% of all known CVEs.
References
Related Vulnerabilities
Other CWE-670 vulnerabilities, ordered by exploit likelihood. View all
| CVE | Severity | CVSS | EPSS | Exploited | Fix |
|---|---|---|---|---|---|
| CVE-2020-9425 | High | 7.5 | 17% | - | Fix |
| CVE-2019-9946 | High | 7.5 | 3.1% | - | Fix |
| CVE-2024-32896 | High | 7.8 | 3.0% | KEV | - |
| CVE-2019-17192 | Critical | 9.8 | 2.7% | - | - |
| CVE-2026-38361 | High | 7.5 | 2.6% | - | - |
| CVE-2020-1914 | Critical | 9.8 | 2.5% | - | Fix |
Embed a live status badge for CVE-2023-41052
Markdown
[](https://tridentstack.com/cve/CVE-2023-41052)HTML
<a href="https://tridentstack.com/cve/CVE-2023-41052"><img src="https://tridentstack.com/cve/badge/CVE-2023-41052.svg" alt="CVE-2023-41052"></a>Find and fix vulnerabilities across your fleet
TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2024-11-21.