Impact
Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossiped blocks. The inbound cleanup step incorrectly downcasts RouterError to VerifyBlockError and discards the penalty, so attackers can repeatedly force block download and Equihash verification without ever being banned. This flaw stems from improper type handling, classified as CWE‑704, which leads to incorrect error processing and undermines the network’s anti‑DoS safeguards.
Affected Systems
All Zebra nodes running any release prior to 6.3.0, including the 6.2.x series, remain vulnerable. The data set does not list specific affected versions, so any pre‑6.3.0 node is considered at risk. Nodes that accept gossip from remote peers are susceptible to repeated invalid block submissions by unauthenticated attackers.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. EPSS data is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a network connection to a target node and the ability to send crafted invalid blocks. No elevated privileges are needed, and the flaw resides in a routine error‑handling path. Attackers could use this to keep malicious peers connected and repeatedly trigger resource‑intensive block validation, thereby causing network churn and potential denial‑of‑service impact to legitimate participants.
OpenCVE Enrichment