{"api_version":"1","generated_at":"2026-07-23T08:58:10+00:00","cve":"CVE-2018-13570","urls":{"html":"https://cve.report/CVE-2018-13570","api":"https://cve.report/api/cve/CVE-2018-13570.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-13570","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-13570"},"summary":{"title":"CVE-2018-13570","description":"The mint function of a smart contract implementation for kkTestCoin1 (KTC1), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-07-09 06:29:00","updated_at":"2018-09-04 14:52:00"},"problem_types":["CWE-190"],"metrics":[],"references":[{"url":"https://github.com/BlockChainsSecurity/EtherTokens/tree/master/ICO","name":"https://github.com/BlockChainsSecurity/EtherTokens/tree/master/ICO","refsource":"MISC","tags":["Third Party Advisory"],"title":"EtherTokens/ICO at master · BlockChainsSecurity/EtherTokens · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/BlockChainsSecurity/EtherTokens/blob/master/GEMCHAIN/mint%20integer%20overflow.md","name":"https://github.com/BlockChainsSecurity/EtherTokens/blob/master/GEMCHAIN/mint%20integer%20overflow.md","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"EtherTokens/mint integer overflow.md at master · BlockChainsSecurity/EtherTokens · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-13570","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-13570","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"13570","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"kktestcoin1_project","cpe5":"kktestcoin1","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"13570","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"kktestcoin1_project","cpe5":"kktestcoin1","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-13570","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The mint function of a smart contract implementation for kkTestCoin1 (KTC1), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://github.com/BlockChainsSecurity/EtherTokens/tree/master/ICO","refsource":"MISC","url":"https://github.com/BlockChainsSecurity/EtherTokens/tree/master/ICO"},{"name":"https://github.com/BlockChainsSecurity/EtherTokens/blob/master/GEMCHAIN/mint%20integer%20overflow.md","refsource":"MISC","url":"https://github.com/BlockChainsSecurity/EtherTokens/blob/master/GEMCHAIN/mint%20integer%20overflow.md"}]}},"nvd":{"publishedDate":"2018-07-09 06:29:00","lastModifiedDate":"2018-09-04 14:52:00","problem_types":["CWE-190"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:kktestcoin1_project:kktestcoin1:-:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"13570","Ordinal":"130219","Title":"CVE-2018-13570","CVE":"CVE-2018-13570","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"13570","Ordinal":"1","NoteData":"The mint function of a smart contract implementation for kkTestCoin1 (KTC1), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"13570","Ordinal":"2","NoteData":"2018-07-09","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"13570","Ordinal":"3","NoteData":"2018-07-08","Type":"Other","Title":"Modified"}]}}}