{"api_version":"1","generated_at":"2026-07-23T14:23:45+00:00","cve":"CVE-2019-18671","urls":{"html":"https://cve.report/CVE-2019-18671","api":"https://cve.report/api/cve/CVE-2019-18671.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-18671","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-18671"},"summary":{"title":"CVE-2019-18671","description":"Insufficient checks in the USB packet handling of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow out-of-bounds writes in the .bss segment via crafted messages. The vulnerability could allow code execution or other forms of impact. It can be triggered by unauthenticated attackers and the interface is reachable via WebUSB.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-12-06 18:15:00","updated_at":"2020-02-12 03:15:00"},"problem_types":["CWE-787"],"metrics":[],"references":[{"url":"https://medium.com/shapeshift-stories/keepkey-release-notes-v-6f7d2ec78065","name":"https://medium.com/shapeshift-stories/keepkey-release-notes-v-6f7d2ec78065","refsource":"MISC","tags":["Release Notes","Third Party Advisory"],"title":"KeepKey Release Notes — v6.2.2. Download the latest KeepKey Client and… | by ShapeShift | ShapeShift Stories | Medium","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://blog.inhq.net/posts/keepkey-CVE-2019-18671/","name":"https://blog.inhq.net/posts/keepkey-CVE-2019-18671/","refsource":"MISC","tags":[],"title":"KeepKey receive buffer vulnerability (VULN-1969) | invd blog","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/keepkey/keepkey-firmware/commit/b222c66cdd7c3203d917c80ba615082d309d80c3","name":"https://github.com/keepkey/keepkey-firmware/commit/b222c66cdd7c3203d917c80ba615082d309d80c3","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"board: factor out tiny_dispatch · keepkey/keepkey-firmware@b222c66 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://medium.com/shapeshift-stories/shapeshift-security-update-8ec89bb1b4e3","name":"https://medium.com/shapeshift-stories/shapeshift-security-update-8ec89bb1b4e3","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"ShapeShift Security Update - ShapeShift Stories - Medium","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-18671","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-18671","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"18671","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"keepkey","cpe5":"keepkey","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"18671","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"keepkey","cpe5":"keepkey","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"18671","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"keepkey","cpe5":"keepkey_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"18671","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"keepkey","cpe5":"keepkey_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-18671","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Insufficient checks in the USB packet handling of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow out-of-bounds writes in the .bss segment via crafted messages. The vulnerability could allow code execution or other forms of impact. It can be triggered by unauthenticated attackers and the interface is reachable via WebUSB."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/keepkey/keepkey-firmware/commit/b222c66cdd7c3203d917c80ba615082d309d80c3","refsource":"MISC","name":"https://github.com/keepkey/keepkey-firmware/commit/b222c66cdd7c3203d917c80ba615082d309d80c3"},{"url":"https://medium.com/shapeshift-stories/keepkey-release-notes-v-6f7d2ec78065","refsource":"MISC","name":"https://medium.com/shapeshift-stories/keepkey-release-notes-v-6f7d2ec78065"},{"refsource":"CONFIRM","name":"https://medium.com/shapeshift-stories/shapeshift-security-update-8ec89bb1b4e3","url":"https://medium.com/shapeshift-stories/shapeshift-security-update-8ec89bb1b4e3"},{"refsource":"MISC","name":"https://blog.inhq.net/posts/keepkey-CVE-2019-18671/","url":"https://blog.inhq.net/posts/keepkey-CVE-2019-18671/"}]}},"nvd":{"publishedDate":"2019-12-06 18:15:00","lastModifiedDate":"2020-02-12 03:15:00","problem_types":["CWE-787"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":10},"severity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:keepkey:keepkey_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"6.2.2","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:keepkey:keepkey:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"18671","Ordinal":"159147","Title":"CVE-2019-18671","CVE":"CVE-2019-18671","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"18671","Ordinal":"1","NoteData":"Insufficient checks in the USB packet handling of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow out-of-bounds writes in the .bss segment via crafted messages. The vulnerability could allow code execution or other forms of impact. It can be triggered by unauthenticated attackers and the interface is reachable via WebUSB.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"18671","Ordinal":"2","NoteData":"2019-12-06","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"18671","Ordinal":"3","NoteData":"2020-02-11","Type":"Other","Title":"Modified"}]}}}