CVE-2019-18673 describes a side-channel vulnerability in SHIFT BitBox02 devices, where the power consumption of the row-based OLED display varies with the number of illuminated pixels, potentially allowing partial recovery of displayed content. The vulnerability has a CVSS score of 4.6 (Medium), indicating a physical attack vector with low complexity, no required privileges or user interaction, and high confidentiality impact. Exploitation requires an attacker to make power consumption measurements via the USB connection while sensitive data, such as a PIN or BIP39 mnemonic, is being displayed. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:shiftcrypto:bitbox02:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.