CVE-2020-14199

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/06/2020
Last modified:
23/06/2020

Description

BIP-143 in the Bitcoin protocol specification mishandles the signing of a Segwit transaction, which allows attackers to trick a user into making two signatures in certain cases, potentially leading to a huge transaction fee. NOTE: this affects all hardware wallets. It was fixed in 1.9.1 for the Trezor One and 2.3.1 for the Trezor Model T.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:satoshilabs:trezor_model_t_firmware:*:*:*:*:*:*:*:* 2.3.1 (excluding)
cpe:2.3:h:satoshilabs:trezor_model_t:-:*:*:*:*:*:*:*
cpe:2.3:o:satoshilabs:trezor_one_firmware:*:*:*:*:*:*:*:* 1.9.1 (excluding)
cpe:2.3:h:satoshilabs:trezor_one:-:*:*:*:*:*:*:*