Back

CVE-2019-18671

CRITICAL

Insufficient checks in the USB packet handling of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow out-of-bounds writes in the .bss segment via crafted messages. The vulnerability could allow code execution or other forms of impact. It can be triggered by unauthenticated attackers and the interface is reachable via WebUSB.

Published: Dec 6, 2019 Modified: Jun 17, 2026
CWE-787

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
keepkey keepkey_firmware * < 6.2.2

GitHub Security Advisory GHSA-xf55-34cc-4qxw

Insufficient checks in the USB packet handling of the ShapeShift KeepKey hardware wallet before...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 3.27%

Top 13% most likely to be exploited

Threat Score 40.2 / 100

Data Sources

NVD EPSS GitHub