Vulnerabilities > CVE-2018-14715 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Cryptogs

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
cryptogs
CWE-338

Summary

The endCoinFlip function and throwSlammer function of the smart contract implementations for Cryptogs, an Ethereum game, generate random numbers with an old block's hash. Therefore, attackers can predict the random number and always win the game.

Vulnerable Configurations

Part Description Count
Application
Cryptogs
1