CVE-2019-15080
A typo in the constructor of the Owned contract (which is inherited by MORPH Token) allows attackers to acquire contract ownership.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.58%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in a smart contract implementation for MORPH Token through 2019-06-05, an Ethereum token. A typo in the constructor of the Owned contract (which is inherited by MORPH Token) allows attackers to acquire contract ownership. A new owner can subsequently obtain MORPH Tokens for free and can perform a DoS attack.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.58% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- morph project/morph
- Source
- cve@mitre.org
References
- https://etherscan.io/address/0x2ef27bf41236bd859a95209e17a43fbd26851f92#contractsThird Party Advisory
- https://github.com/smsecgroup/SM-VUL/tree/master/typo-vul-02Exploit, Third Party Advisory
- https://etherscan.io/address/0x2ef27bf41236bd859a95209e17a43fbd26851f92#contractsThird Party Advisory
- https://github.com/smsecgroup/SM-VUL/tree/master/typo-vul-02Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.