CVE-2018-17987 describes a high-severity vulnerability (CVSS 7.5) in the HashHeroes Tiles Ethereum game, specifically within the determineWinner function of its smart contract. An attacker can manipulate the prize awarding by being the final tile purchaser, due to the game's reliance on a predictable blockhash for randomness when all tiles are sold. This allows for a complete integrity compromise (I:H) with low attack complexity and no user interaction required. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:hashheroes:hashheroes:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.