Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xf55-34cc-4qxw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Insufficient checks in the USB packet handling of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow out-of-bounds writes on the stack via crafted messages. The vulnerability could allow code execution or other forms of impact. It can be triggered by unauthenticated attackers and the interface is reachable via WebUSB.

Insufficient checks in the USB packet handling of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow out-of-bounds writes on the stack via crafted messages. The vulnerability could allow code execution or other forms of impact. It can be triggered by unauthenticated attackers and the interface is reachable via WebUSB.

EPSS

Процентиль: 90%
0.05931
Низкий

Связанные уязвимости

CVSS3: 9.8
nvd
около 6 лет назад

Insufficient checks in the USB packet handling of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow out-of-bounds writes in the .bss segment via crafted messages. The vulnerability could allow code execution or other forms of impact. It can be triggered by unauthenticated attackers and the interface is reachable via WebUSB.

EPSS

Процентиль: 90%
0.05931
Низкий