CVE-2018-10769
HIGHSmartMesh - Unauthorized Asset Transfer via Replay Attack
Title source: llmDescription
The transferProxy and approveProxy functions of a smart contract implementation for SmartMesh (SMT), an Ethereum ERC20 token, allow attackers to accomplish an unauthorized transfer of digital assets because replay attacks can occur with the same-named functions (with the same signatures) in other tokens: First (FST), GG Token (GG), M2C Mesh Network (MTC), M2C Mesh Network (mesh), and UG Token (UGT).
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/nkbai/defcon26/blob/master/docs/Replay%20Attacks%20on%20Ethereum%20Smart%20Contracts.md
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef%40%3Cdev.struts.apache.org%3E
Scores
CVSS v3
7.5
EPSS
0.0094
EPSS Percentile
57.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
Status
published
Products (6)
first_project/first
gg_token_project/gg_token
mesh_project/mesh
mtc_project/mtc
smartmesh_project/smartmesh
ugtoken_project/ugtoken
Published
Aug 10, 2018
Tracked Since
Feb 18, 2026