Vulnerabilities > CVE-2018-10666 - Unspecified vulnerability in Auroradao Idex Membership

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
auroradao

Summary

The Owned smart contract implementation for Aurora IDEX Membership (IDXM), an Ethereum ERC20 token, allows attackers to acquire contract ownership because the setOwner function is declared as public. A new owner can subsequently modify variables.

Vulnerable Configurations

Part Description Count
Application
Auroradao
1