CVE-2022-40769
HIGHCVSS 7.5/10EPSS 1.01%
Last modified
CVE-2022-40769 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. profanity through 1.60 has only four billion possible RNG initializations. Thus, attackers can recover private keys from Ethereum vanity addresses and steal cryptocurrency, as exploited in the wild in June 2022.. EPSS estimates a 1.01% chance of exploitation in the next 30 days.
Description
profanity through 1.60 has only four billion possible RNG initializations. Thus, attackers can recover private keys from Ethereum vanity addresses and steal cryptocurrency, as exploited in the wild in June 2022.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Profanity Project | Profanity | <= 1.60 |
References
- https://github.com/johguse/profanityThird Party Advisory
- https://github.com/johguse/profanity/issues/61Issue Tracking, Third Party Advisory
- https://github.com/johguse/profanityThird Party Advisory
- https://github.com/johguse/profanity/issues/61Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-40769?
profanity through 1.60 has only four billion possible RNG initializations. Thus, attackers can recover private keys from Ethereum vanity addresses and steal cryptocurrency, as exploited in the wild in June 2022.
How severe is CVE-2022-40769?
CVE-2022-40769 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 1.01% probability of exploitation in the next 30 days.
How do I fix CVE-2022-40769?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-40761The function tee_obj_free in Samsung mTower through 0.3.0 al…7.5
- CVE-2022-40762A Memory Allocation with Excessive Size Value vulnerablity i…7.5
- CVE-2022-40764Snyk CLI before 1.996.0 allows arbitrary command execution, …7.8
- CVE-2022-40765A vulnerability in the Edge Gateway component of Mitel MiVoi…6.8
- CVE-2022-40766Modern Campus Omni CMS (formerly OU Campus) 10.2.4 allows lo…9.8
- CVE-2022-40768drivers/scsi/stex.c in the Linux kernel through 5.19.9 allow…5.5
- CVE-2022-4077Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-40770Zoho ManageEngine ServiceDesk Plus versions 13010 and prior …7.2
- CVE-2022-40771Zoho ManageEngine ServiceDesk Plus versions 13010 and prior …4.9
- CVE-2022-40772Zoho ManageEngine ServiceDesk Plus versions 13010 and prior …6.5
- CVE-2022-40773Zoho ManageEngine ServiceDesk Plus MSP before 10609 and Supp…8.8
- CVE-2022-40774An issue was discovered in Bento4 through 1.6.0-639. There i…5.5
Are you affected by CVE-2022-40769?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
