CVE-2018-6875

HIGH

KeepKey Firmware 4.0.0 - Information Disclosure via Format String Vulnerability

Title source: llm
STIX 2.1

Description

Format String vulnerability in KeepKey version 4.0.0 allows attackers to trigger information display (of information that should not be accessible), related to text containing characters that the device's font lacks.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0111
EPSS Percentile 61.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-134
Status published
Products (1)
shapeshift/keepkey_firmware 4.0.0
Published Mar 14, 2018
Tracked Since Feb 18, 2026