SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-15552

Therefore, it allows attackers to always win and get rewards.

HIGH 7.5EPSS 1.17%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The "PayWinner" function of a simplelottery smart contract implementation for The Ethereum Lottery, an Ethereum gambling game, generates a random value with publicly readable variable "maxTickets" (which is private, yet predictable and readable by the eth.getStorageAt function). Therefore, it allows attackers to always win and get rewards.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
1.17% probability · 66th percentile
CISA KEV
Not listed
Weakness
CWE-338
Affected
theethereumlottery/the ethereum lottery
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.