OLED Display Vulnerability in Trezor One Devices by SatoshiLabs
CVE-2019-14353

4.2MEDIUM

Key Information:

Vendor

Trezor

Vendor
CVE Published:
8 August 2019

What is CVE-2019-14353?

The Trezor One devices prior to version 1.8.2 expose a significant side channel vulnerability through their OLED displays. This issue arises from the variation in power consumption depending on the number of illuminated pixels during display cycles, which can lead to partial recovery of displayed contents. Attackers with access to the USB connection could exploit this vulnerability to measure power consumption, potentially revealing sensitive information like PINs and BIP39 mnemonics. It’s crucial to note that this vulnerability is only exploitable when secret data is actively displayed, emphasizing the importance of securing the USB connection against unauthorized access.

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.