CVE-2022-40769

HIGH EXPLOITED

profanity <1.60 - Info Disclosure

Title source: llm

Description

profanity through 1.60 has only four billion possible RNG initializations. Thus, attackers can recover private keys from Ethereum vanity addresses and steal cryptocurrency, as exploited in the wild in June 2022.

Exploits (1)

nomisec WRITEUP 1 stars
by PLSRcoin · poc
https://github.com/PLSRcoin/CVE-2022-40769

Scores

CVSS v3 7.5
EPSS 0.0066
EPSS Percentile 71.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2022-09-18
CWE
CWE-338
Status published
Products (1)
profanity_project/profanity < 1.60
Published Sep 18, 2022
Tracked Since Feb 18, 2026