PT-2019-9928 · Ethereum · Cryptbond Network

Published

2019-12-31

·

Updated

2020-01-14

·

CVE-2018-19831

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cryptbond Network (CBN) (affected versions not specified)
Description The issue concerns the ToOwner() function of a smart contract implementation for Cryptbond Network (CBN), which is an tradable Ethereum ERC20 token. This function allows attackers to change the owner of the contract because it does not check the caller's identity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-19831

Affected Products

Cryptbond Network