CVE-2019-18672
Summary
| CVE | CVE-2019-18672 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-06 18:15:00 UTC |
| Updated | 2020-03-02 15:15:00 UTC |
| Description | Insufficient checks in the finite state machine of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow a partial reset of cryptographic secrets to known values via crafted messages. Notably, this breaks the security of U2F for new server registrations and invalidates existing registrations. This vulnerability can be exploited by unauthenticated attackers and the interface is reachable via WebUSB. |
Risk And Classification
Problem Types: CWE-354
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Shapeshift | Keepkey Firmware | - | All | All | All |
| Hardware | Shapeshift | Keepkey Firmware | - | All | All | All |
| Operating System | Shapeshift | Keepkey Firmware | All | All | All | All |
| Operating System | Shapeshift | Keepkey Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| KeepKey Release Notes — v6.2.2. Download the latest KeepKey Client and… | by ShapeShift | ShapeShift Stories | Medium | MISC | medium.com | Third Party Advisory |
| firmware: stronger recovery state machine checks · keepkey/keepkey-firmware@769714f · GitHub | MISC | github.com | Patch, Third Party Advisory |
| ShapeShift Security Update - ShapeShift Stories - Medium | CONFIRM | medium.com | Third Party Advisory |
| KeepKey key erasure vulnerability (VULN-1971) | invd blog | MISC | blog.inhq.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.