CVE-2019-14359
Last modified
CVE-2019-14359 is a vulnerability of currently unknown severity. On BC Vault devices, a side channel for the row-based SSD1309 OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
On BC Vault devices, a side channel for the row-based SSD1309 OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage this behavior to recover a data value. In other words, the side channel is relevant only if the attacker has enough control over the device's USB connection to make power-consumption measurements at a time when secret data is displayed. The side channel is not relevant in other circumstances, such as a stolen device that is not currently displaying secret data. NOTE: the vendor's position is that there is no security impact: the only potentially leaked information is the number of characters in the PIN
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Real-Sec | Bc Vault Firmware | All versions |
References
- https://bc-vault.com/2019/08/our-response-to-cve-2019-14359Exploit, Third Party Advisory
- https://bc-vault.com/2019/08/our-response-to-cve-2019-14359Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-14359?
How severe is CVE-2019-14359?
How do I fix CVE-2019-14359?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-14353On Trezor One devices before 1.8.2, a side channel for the r…
- CVE-2019-14354On Ledger Nano S and Nano X devices, a side channel for the …
- CVE-2019-14355On ShapeShift KeepKey devices, a side channel for the row-ba…
- CVE-2019-14356On Coldcard MK1 and MK2 devices, a side channel for the row-…5.3
- CVE-2019-14357On Mooltipass Mini devices, a side channel for the row-based…
- CVE-2019-14358On Archos Safe-T devices, a side channel for the row-based O…4.6
- CVE-2019-1436An information disclosure vulnerability exists when the win3…5.5
- CVE-2019-14360On Hyundai Pay Kasse HK-1000 devices, a side channel for the…4.6
- CVE-2019-14361Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-14362Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Tr…
- CVE-2019-14363A stack-based buffer overflow in the upnpd binary running on…
- CVE-2019-14364An XSS vulnerability in the "Email Subscribers & Newsletters…6.1
Are you affected by CVE-2019-14359?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
