CVE-2018-10666 describes a critical vulnerability in the Aurora IDEX Membership (IDXM) Ethereum ERC20 token's smart contract, specifically affecting the 'Owned' implementation. The flaw allows an attacker to seize contract ownership due to the 'setOwner' function being publicly accessible, enabling subsequent modification of contract variables. This vulnerability carries a high CVSS score of 7.5, indicating a network-exploitable attack with low complexity and high impact on integrity, yet it shows a very low EPSS score and no evidence of active exploitation or public exploit code. Despite its severity, there is no community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:auroradao:idex_membership:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.