Impact
A flaw in Chia Blockchain 2.1.0 allows an attacker with local access to bypass authentication in the RPC Server Master Passphrase Handler and retrieve a private key. The vulnerability is classified as CWE‑287 and CWE‑306. The description states that the attack has high complexity and is difficult to exploit, yet an exploit has been published. If successful, the attacker can recover the private key used by the wallet.
Affected Systems
Chia Blockchain version 2.1.0 is affected. No other versions or products are listed as impacted.
Risk and Exploitability
The CVSS score is 2, indicating low severity, and the EPSS score is under 1%, meaning exploitation is unlikely. The vulnerability is not in the CISA KEV catalog. The attack vector is local only, so it requires the attacker to have host access to a running Chia node with the RPC server enabled.
OpenCVE Enrichment