Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jjq4-78fg-7j7h

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.1.0 allow a stack buffer overflow via crafted messages. The overflow in ethereum_extractThorchainSwapData() in ethereum.c can circumvent stack protections and lead to code execution. The vulnerable interface is reachable remotely over WebUSB.

Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.1.0 allow a stack buffer overflow via crafted messages. The overflow in ethereum_extractThorchainSwapData() in ethereum.c can circumvent stack protections and lead to code execution. The vulnerable interface is reachable remotely over WebUSB.

EPSS

Процентиль: 84%
0.02202
Низкий

8.8 High

CVSS3

Дефекты

CWE-120
CWE-787

Связанные уязвимости

CVSS3: 8.8
nvd
почти 5 лет назад

Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.1.0 allow a stack buffer overflow via crafted messages. The overflow in ethereum_extractThorchainSwapData() in ethereum.c can circumvent stack protections and lead to code execution. The vulnerable interface is reachable remotely over WebUSB.

EPSS

Процентиль: 84%
0.02202
Низкий

8.8 High

CVSS3

Дефекты

CWE-120
CWE-787