Show plain JSON{"id": "CVE-2018-12975", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 7.5, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 3.6, "exploitabilityScore": 3.9}]}, "published": "2018-09-24T22:29:00.427", "references": [{"url": "https://medium.com/%40jonghyk.song/create-legendary-champs-by-breaking-prng-of-cryptosaga-an-ethereum-rpg-game-cve-2018-12975-8de733ff8255", "source": "cve@mitre.org"}, {"url": "https://medium.com/%40jonghyk.song/create-legendary-champs-by-breaking-prng-of-cryptosaga-an-ethereum-rpg-game-cve-2018-12975-8de733ff8255", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-338"}]}], "descriptions": [{"lang": "en", "value": "The random() function of the smart contract implementation for CryptoSaga, an Ethereum game, generates a random value with publicly readable variables such as timestamp, the current block's blockhash, and a private variable (which can be read with a getStorageAt call). Therefore, attackers can precompute the random number and manipulate the game (e.g., get powerful characters or get critical damages)."}, {"lang": "es", "value": "La funci\u00f3n random() de una implementaci\u00f3n de contrato inteligente de CryptoSaga, un juego de Ethereum, genera un valor aleatorio con variables legibles globalmente como la marca de tiempo, el hash del bloque actual y una variable privada (que se puede leer con una llamada getStorageAt). Por lo tanto, los atacantes pueden precalcular el n\u00famero aleatorio y manipular el juego (p.ej., obtener personajes poderosos o conseguir proporcionar da\u00f1o cr\u00edtico)."}], "lastModified": "2024-11-21T03:46:10.437", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:cryptosaga:cryptosaga:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E12CCEBC-C27E-49EE-ABD0-158F0EA446FA"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}