CVE-2019-14360 identifies a medium-severity side-channel vulnerability in Hyundai Pay Kasse HK-1000 devices, where power consumption fluctuations of the row-based OLED display can allow partial recovery of displayed confidential data, such as PINs or BIP39 mnemonics. Exploitation requires a physical attack vector, specifically an attacker with control over the device's USB connection to measure power consumption while sensitive information is actively displayed. This condition-dependent vulnerability carries a CVSS score of 4.6, indicating a high confidentiality impact if the precise attack scenario is met. There is currently no evidence of active exploitation, public exploit code, or significant community discussion or media coverage related to this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:hyundai-pay:kasse_hk-1000_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.