← back
CVE-2021-31616

CVE-2021-31616

EPSS 2.5%
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 2.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
06 May 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.1.0 allow a stack buffer overflow via crafted messages. The overflow in ethereum_extractThorchainSwapData() in ethereum.c can circumvent stack protections and lead to code execution. The vulnerable interface is reachable remotely over WebUSB.
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →