CVE-2018-10769

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/08/2018
Last modified:
07/11/2023

Description

The transferProxy and approveProxy functions of a smart contract implementation for SmartMesh (SMT), an Ethereum ERC20 token, allow attackers to accomplish an unauthorized transfer of digital assets because replay attacks can occur with the same-named functions (with the same signatures) in other tokens: First (FST), GG Token (GG), M2C Mesh Network (MTC), M2C Mesh Network (mesh), and UG Token (UGT).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:smartmesh_project:smartmesh:-:*:*:*:*:*:*:*
cpe:2.3:a:ugtoken_project:ugtoken:-:*:*:*:*:*:*:*
cpe:2.3:a:gg_token_project:gg_token:-:*:*:*:*:*:*:*
cpe:2.3:a:first_project:first:-:*:*:*:*:*:*:*
cpe:2.3:a:mtc_project:mtc:-:*:*:*:*:*:*:*
cpe:2.3:a:mesh_project:mesh:-:*:*:*:*:*:*:*