{"id":"CVE-2022-30330","details":"In the KeepKey firmware before 7.3.2,Flaws in the supervisor interface can be exploited to bypass important security restrictions on firmware operations. Using these flaws, malicious firmware code can elevate privileges, permanently make the device inoperable or overwrite the trusted bootloader code to compromise the hardware wallet across reboots or storage wipes.","modified":"2026-08-12T13:01:04.153120Z","published":"2022-05-07T03:25:34Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/30xxx/CVE-2022-30330.json"},"references":[{"type":"WEB","url":"https://github.com/keepkey/keepkey-firmware/releases/tag/v7.3.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/30xxx/CVE-2022-30330.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-30330"},{"type":"FIX","url":"https://github.com/keepkey/keepkey-firmware/commit/447c1f038a31378ab9589965c098467d9ea6cccc"},{"type":"ARTICLE","url":"https://blog.inhq.net/posts/keepkey-CVE-2022-30330/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/keepkey/keepkey-firmware","events":[{"introduced":"0"},{"fixed":"0591b1ce9f604c19a1b90bbf743f8f7606ae8722"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"7.3.2"}],"source":"DESCRIPTION"}}],"versions":["v7.2.1","v7.1.7","v7.1.8","v7.1.5","v7.1.4","v7.1.2","v7.1.1","v7.1.0","v7.0.3","v6.7.0","v6.6.0","v6.5.1","v6.4.0","docker-v13","v6.3.0","v6.2.2","v6.2.0-hotfix.0","v6.2.0","v6.1.1","v6.1.0","bl_v2.0.0","v5.11.0","v5.10.1","wl_k114wlda_v2","wl_k114wlbp_v2","v5.9.1","v5.9.0","v5.5.0","v5.4.1","v5.3.0","v5.1.2","v5.1.1","v5.1.0","docker-v3","v5.0.1","v4.0.0","v3.1.0","v3.0.18","v2.2.0","v2.1.0","v2.0.12","v2.0.11","v2.0.9","v1.2.0-rc.1","v1.2.0-rc","v1.2.0","v1.1.0","v1.0.5","v1.0.3","v1.0.1","v1.0.0","v1.0.0rc1"],"database_specific":{"vanir_signatures_modified":"2026-08-12T13:01:04Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/keepkey/keepkey-firmware/commit/0591b1ce9f604c19a1b90bbf743f8f7606ae8722","target":{"function":"check_bootloader","file":"tools/firmware/keepkey_main.c"},"deprecated":false,"digest":{"function_hash":"294123191815334012997121978248847040035","length":477},"id":"CVE-2022-30330-433a3d61"},{"target":{"file":"tools/blupdater/main.c","function":"unknown_bootloader"},"deprecated":false,"digest":{"function_hash":"292003018493310952547530825061636564952","length":332},"id":"CVE-2022-30330-470f76da","signature_type":"Function","signature_version":"v1","source":"https://github.com/keepkey/keepkey-firmware/commit/0591b1ce9f604c19a1b90bbf743f8f7606ae8722"},{"deprecated":false,"digest":{"function_hash":"116830319557477195367067723787426946390","length":1609},"id":"CVE-2022-30330-4bd28af0","signature_type":"Function","signature_version":"v1","source":"https://github.com/keepkey/keepkey-firmware/commit/0591b1ce9f604c19a1b90bbf743f8f7606ae8722","target":{"file":"lib/board/check_bootloader.c","function":"get_bootloaderKind"}},{"deprecated":false,"digest":{"line_hashes":["44611891952244110137375183281031675443","285428054455441636551810293750827266429","238945426805892685539688189408648265507","275047964691103085612777863797520235928"],"threshold":0.9},"id":"CVE-2022-30330-6362b26e","signature_type":"Line","signature_version":"v1","source":"https://github.com/keepkey/keepkey-firmware/commit/0591b1ce9f604c19a1b90bbf743f8f7606ae8722","target":{"file":"tools/blupdater/main.c"}},{"deprecated":false,"digest":{"line_hashes":["44611891952244110137375183281031675443","312802404481325664305582578438073565422","206495168246894855798233768397014041279","191737711206465611254906142848055955884"],"threshold":0.9},"id":"CVE-2022-30330-9d9d19a1","signature_type":"Line","signature_version":"v1","source":"https://github.com/keepkey/keepkey-firmware/commit/0591b1ce9f604c19a1b90bbf743f8f7606ae8722","target":{"file":"lib/board/keepkey_flash.c"}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/keepkey/keepkey-firmware/commit/0591b1ce9f604c19a1b90bbf743f8f7606ae8722","target":{"file":"tools/firmware/keepkey_main.c"},"deprecated":false,"digest":{"line_hashes":["100486001065654198556583097111432050866","324704991906621117028231293143300007857","289206258741950998795293187606917836369","160740731416919829693198335420396944711","83245503881923196889459922263061078844","275628103680180835140189982885236430416","233408394917263064509023569219007779968","225687162349266686323325860628937650243","314150643277007710007947557131622118644"],"threshold":0.9},"id":"CVE-2022-30330-9e728fbb"},{"deprecated":false,"digest":{"function_hash":"107269180900077278528261167648131053723","length":777},"id":"CVE-2022-30330-a912fc20","signature_type":"Function","signature_version":"v1","source":"https://github.com/keepkey/keepkey-firmware/commit/0591b1ce9f604c19a1b90bbf743f8f7606ae8722","target":{"file":"lib/board/keepkey_flash.c","function":"flash_programModel"}},{"digest":{"line_hashes":["188621247341080256233441335575939154225","259373863761664844412612366561944438166","282212781327136127667729445878463542616","309067033668450140011323100507921825959","303948376131732361393495404646008295580","183883622822530225792083245797793737027","336312453251804640968890216457717990935"],"threshold":0.9},"id":"CVE-2022-30330-cf8739b9","signature_type":"Line","signature_version":"v1","source":"https://github.com/keepkey/keepkey-firmware/commit/0591b1ce9f604c19a1b90bbf743f8f7606ae8722","target":{"file":"lib/board/check_bootloader.c"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["166170415739160617500600119944133374065","211746958265260322046587769297945740896","263317472117347925626166367616046917449","293323260150058115567354305275795986022","159520476636501467449652118052637211635","251048974044874976237070641682657099010","210163504328892399685724825243540497966","157785186458539734999334610881965610621"],"threshold":0.9},"id":"CVE-2022-30330-eb733228","signature_type":"Line","signature_version":"v1","source":"https://github.com/keepkey/keepkey-firmware/commit/0591b1ce9f604c19a1b90bbf743f8f7606ae8722","target":{"file":"include/keepkey/board/check_bootloader.h"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-30330.json"}}],"schema_version":"1.9.0"}