ZeroHour

CVE-2018-10705

PoC
CVSS 3.0
7.5 high
EPSS
1%p64
Published
()
Modified
Description

The Owned smart contract implementation for Aurora DAO (AURA), an Ethereum ERC20 token, allows attackers to acquire contract ownership because the setOwner function is declared as public. An attacker can then conduct a lockBalances() denial of service attack.

Vendors
auroradao
Products
aura
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.