CVE-2018-10468 describes a critical vulnerability in the Useless Ethereum Token (UET) smart contract, specifically within its transferFrom function. This flaw allows attackers to steal all assets from victims' accounts due to incorrect value computations. Rated 7.5 HIGH, the vulnerability is easily exploitable over the network with no user interaction, leading to a complete loss of confidentiality. Although exploited in the wild starting in December 2017, there is no public exploit code, Metasploit module, or significant community discussion, and it is not listed on the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:uetoken:useless_ethereum_token:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.