Back
CVE-2019-18671
CRITICAL
Insufficient checks in the USB packet handling of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow out-of-bounds writes in the .bss segment via crafted messages. The vulnerability could allow code execution or other forms of impact. It can be triggered by unauthenticated attackers and the interface is reachable via WebUSB.
Published: Dec 6, 2019
Modified: Jun 17, 2026
CWE-787
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| keepkey | keepkey_firmware | * < 6.2.2 |
GitHub Security Advisory GHSA-xf55-34cc-4qxw
Insufficient checks in the USB packet handling of the ShapeShift KeepKey hardware wallet before...
References (8)
- https://blog.inhq.net/posts/keepkey-CVE-2019-18671/
- https://github.com/keepkey/keepkey-firmware/commit/b222c66cdd7c3203d917c80ba615082d309d80c3 Patch, Third Party Advisory
- https://medium.com/shapeshift-stories/keepkey-release-notes-v-6f7d2ec78065 Release Notes, Third Party Advisory
- https://medium.com/shapeshift-stories/shapeshift-security-update-8ec89bb1b4e3 Third Party Advisory
- https://blog.inhq.net/posts/keepkey-CVE-2019-18671/
- https://github.com/keepkey/keepkey-firmware/commit/b222c66cdd7c3203d917c80ba615082d309d80c3 Patch, Third Party Advisory
- https://medium.com/shapeshift-stories/keepkey-release-notes-v-6f7d2ec78065 Release Notes, Third Party Advisory
- https://medium.com/shapeshift-stories/shapeshift-security-update-8ec89bb1b4e3 Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
3.27%
Top 13% most likely to be exploited
Threat Score
40.2 / 100
Data Sources
NVD
EPSS
GitHub