PT-2019-9590 · Primeo · Primeo

Publicado

2019-06-19

·

Atualizado

2019-06-24

·

CVE-2018-18425

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Primeo (PEO) smart contract implementation (affected versions not specified)
Description The issue concerns the doAirdrop function in the smart contract implementation, which fails to validate the numerical relationship between the airdrop amount and the token's total supply. This allows the contract owner to issue an arbitrary amount of currency, effectively increasing the total supply beyond the hard cap defined in the contract and devaluing the token.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Insufficiently Random Values

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-18425

Produtos afetados

Primeo