CVE-2019-16398: High severity keeper k5 firmware vulnerability
Published Sep 19, 2019
·Updated
On Keeper K5 20.1.0.25 and 20.1.0.63 devices, remote code execution can occur by inserting an SD card containing a file named zskjscriptrun.sh that executes a reverse shell.
Affected Software
3 affected components
Keeper K5 Firmware=20.1.0.25
Keeper K5 Firmware=20.1.0.63
Keeper K5
Event History
Sep 19, 2019
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-16398?
CVE-2019-16398 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2019-16398?
To mitigate CVE-2019-16398, update the Keeper K5 firmware to a version that is not affected.
3
What devices are affected by CVE-2019-16398?
CVE-2019-16398 affects Keeper K5 devices running firmware versions 20.1.0.25 and 20.1.0.63.
4
What type of attack does CVE-2019-16398 enable?
CVE-2019-16398 enables a remote code execution attack through the use of a malicious SD card.
5
Is there a known exploit for CVE-2019-16398?
Yes, the exploit for CVE-2019-16398 involves using an SD card with a specific script to execute a reverse shell.