CVE-2019-14353 describes a side-channel vulnerability in Trezor One devices running firmware versions prior to 1.8.2, where power consumption variations of the OLED display could allow partial recovery of displayed secrets like PINs or BIP39 mnemonics. This medium-severity vulnerability (CVSS 4.2) requires a physical attacker with control over the device's USB connection to measure power consumption while sensitive data is actively displayed. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.2CPE matchmatch criteria | cpe:2.3:o:trezor:one_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.