Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-18672

Опубликовано: 06 дек. 2019
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Insufficient checks in the finite state machine of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow a partial reset of cryptographic secrets to known values via crafted messages. Notably, this breaks the security of U2F for new server registrations and invalidates existing registrations. This vulnerability can be exploited by unauthenticated attackers and the interface is reachable via WebUSB.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:shapeshift:keepkey_firmware:*:*:*:*:*:*:*:*
Версия до 6.2.2 (исключая)
cpe:2.3:h:shapeshift:keepkey_firmware:-:*:*:*:*:*:*:*

EPSS

Процентиль: 64%
0.00477
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-354

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

Insufficient checks in the finite state machine of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow a partial reset of cryptographic secrets to known values via crafted messages. Notably, this breaks the security of U2F for new server registrations and invalidates existing registrations. This vulnerability can be exploited by unauthenticated attackers and the interface is reachable via WebUSB.

EPSS

Процентиль: 64%
0.00477
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-354