← Back to browse · API

CVE-2018-3972

Severity
CRITICAL
CVSS
10.0
EPSS
0.03686
Risk score
41.29
CISA KEV
No
PoC
No
Published
2018-09-26
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2018-15758, GHSA-4844-9F5J-F96X
Products
https://github.com/sabelnikov:Epee as used in Monero 'Lithium Luna' (v0.12.2.0-master-ffab6700)
Sources
euvd EUVD-2018-15758

Description

An exploitable code execution vulnerability exists in the Levin deserialization functionality of the Epee library, as used in Monero 'Lithium Luna' (v0.12.2.0-master-ffab6700) and other cryptocurrencies. A specially crafted network packet can cause a logic flaw, resulting in code execution. An attacker can send a packet to trigger this vulnerability.

References