CVE-2018-10299
45Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 2.8%
from disclosure to weapon18 days
Published on NVDApr 23
1st PoC+18d
VulnCheckApr 23
exploitation probability
2.8%top 15% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem Coin (BEC), the Ethereum ERC20 token used in the Beauty Chain economic system, allows attackers to accomplish an unauthorized increase of digital assets by providing two _receivers arguments in conjunction with a large _value argument, as exploited in the wild in April 2018, aka the "batchOverflow" issue.
Affected products
n/a · n/apublic PoCs found — 1
vulncheckvulncheck.com/xdb/71842891a6c7unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://dasp.co/#item-3https://medium.com/secbit-media/a-disastrous-vulnerability-found-in-smart-contracts-of-beautychain-bec-dbf24ddbc30ehttps://peckshield.com/2018/04/22/batchOverflow/https://support.okex.com/hc/en-us/articles/360002944212-BeautyChain-BEC-Withdrawal-and-Trading-Suspendedhttps://twitter.com/OKEx_/status/987967343983714304https://www.reddit.com/r/ethereum/comments/8esyg9/okex_erc20_bug/