CVE-2018-10769
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/08/2018
Last modified:
07/11/2023
Description
The transferProxy and approveProxy functions of a smart contract implementation for SmartMesh (SMT), an Ethereum ERC20 token, allow attackers to accomplish an unauthorized transfer of digital assets because replay attacks can occur with the same-named functions (with the same signatures) in other tokens: First (FST), GG Token (GG), M2C Mesh Network (MTC), M2C Mesh Network (mesh), and UG Token (UGT).
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:smartmesh_project:smartmesh:-:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ugtoken_project:ugtoken:-:*:*:*:*:*:*:* | ||
| cpe:2.3:a:gg_token_project:gg_token:-:*:*:*:*:*:*:* | ||
| cpe:2.3:a:first_project:first:-:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mtc_project:mtc:-:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mesh_project:mesh:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



