Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-30330

Опубликовано: 07 мая 2022
Источник: nvd
CVSS3: 6.6
CVSS2: 6.9
EPSS Низкий

Описание

In the KeepKey firmware before 7.3.2,Flaws in the supervisor interface can be exploited to bypass important security restrictions on firmware operations. Using these flaws, malicious firmware code can elevate privileges, permanently make the device inoperable or overwrite the trusted bootloader code to compromise the hardware wallet across reboots or storage wipes.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:keepkey:keepkey_firmware:*:*:*:*:*:*:*:*
Версия до 7.3.2 (исключая)
cpe:2.3:h:keepkey:keepkey:-:*:*:*:*:*:*:*

EPSS

Процентиль: 22%
0.0007
Низкий

6.6 Medium

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.6
github
больше 3 лет назад

In the KeepKey firmware before 7.3.2, the bootloader can be exploited in unusual situations in which the attacker has physical access, convinces the victim to install malicious firmware, or knows the victim's seed phrase. lib/board/supervise.c mishandles svhandler_flash_* address range checks. If exploited, any installed malware could persist even after wiping the device and resetting the firmware.

EPSS

Процентиль: 22%
0.0007
Низкий

6.6 Medium

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-20