CVE-2020-15302: Argent Recoverymanager

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

In Argent RecoveryManager before 0xdc350d09f71c48c5D22fBE2741e4d6A03970E192, the executeRecovery function does not require any signatures in the zero-guardian case, which allows attackers to cause a denial of service (locking) or a takeover.

Affected products

  • Argent Recoverymanager: before 0xdc350d09f71c48c5d22fbe2741e4d6a03970e192 (fixed in 0xdc350d09f71c48c5d22fbe2741e4d6a03970e192)

Published 2020-06-25. Last modified 2026-06-17.