8.8

CVE-2021-31616

Exploit
Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.1.0 allow a stack buffer overflow via crafted messages. The overflow in ethereum_extractThorchainSwapData() in ethereum.c can circumvent stack protections and lead to code execution. The vulnerable interface is reachable remotely over WebUSB.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ShapeshiftKeepkey Firmware Version >= 7.0.3 < 7.1.0
   ShapeshiftKeepkey Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.5% 0.826
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://blog.inhq.net/posts/keepkey-CVE-2021-31616/
Patch
Third Party Advisory
Exploit
https://github.com/keepkey/keepkey-firmware/commit/e49d45594002d4d3fbc1f03488e6dfc0a0a65836
Patch
Third Party Advisory
https://github.com/keepkey/keepkey-firmware/releases/tag/v7.1.0
Third Party Advisory
Release Notes
https://shapeshift.com/library/keepkey-important-update-issued-april-4-required
Vendor Advisory