SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-10299

An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem Coin (BEC), the Ethereum ERC20 token used in the Beauty Chain economic system, allows attackers to accomplish an unauthorized increase of digital…

HIGH 7.5EPSS 2.67%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.67%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem Coin (BEC), the Ethereum ERC20 token used in the Beauty Chain economic system, allows attackers to accomplish an unauthorized increase of digital assets by providing two _receivers arguments in conjunction with a large _value argument, as exploited in the wild in April 2018, aka the "batchOverflow" issue.

CVSS 3.0
7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
2.67% probability · 85th percentile
CISA KEV
Not listed
Weakness
CWE-190
Affected
beauty/beauty ecosystem coin
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.