CVE-2019-14357 describes a side-channel vulnerability in Mooltipass Mini devices, specifically affecting the mooltipass_mini and mooltipass_mini_firmware products. This vulnerability allows for partial recovery of display contents by analyzing power consumption fluctuations tied to the number of illuminated pixels on the OLED screen. The attack requires physical proximity and control over the device's USB connection to measure power consumption while sensitive data, such as a PIN, is displayed. The vulnerability has a low CVSS score of 2.4 (AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N), indicating a physical attack vector with low complexity and a limited impact on confidentiality. The vendor considers the attack not "realistically implementable." There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion and media coverage are minimal, suggesting a low level of attention and perceived threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:mooltipass:mooltipass_mini_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.