Vulnerabilities
Vulnerable Software
Insufficient checks in the finite state machine of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow a partial reset of cryptographic secrets to known values via crafted messages. Notably, this breaks the security of U2F for new server registrations and invalidates existing registrations. This vulnerability can be exploited by unauthenticated attackers and the interface is reachable via WebUSB.
CVSS Score
7.5
EPSS Score
0.005
Published
2019-12-06
Format String vulnerability in KeepKey version 4.0.0 allows attackers to trigger information display (of information that should not be accessible), related to text containing characters that the device's font lacks.
CVSS Score
7.5
EPSS Score
0.003
Published
2018-03-14


Contact Us

Shodan ® - All rights reserved