CVE-2021-31616
CVE-2021-31616
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 2.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
06 May 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.1.0 allow a stack buffer overflow via crafted messages. The overflow in ethereum_extractThorchainSwapData() in ethereum.c can circumvent stack protections and lead to code execution. The vulnerable interface is reachable remotely over WebUSB.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →