Learn about CVE-2019-14356, a side channel vulnerability in Coldcard MK1 and MK2 devices' OLED display, enabling attackers to retrieve sensitive data like PIN and BIP39 mnemonic. Find out the impact, technical details, and mitigation steps.
Coldcard MK1 and MK2 devices have a side channel vulnerability in the row-based OLED display, potentially exposing sensitive data like PIN and BIP39 mnemonic.
Understanding CVE-2019-14356
Coldcard MK1 and MK2 devices are susceptible to a side channel vulnerability in the row-based OLED display, allowing attackers to potentially retrieve confidential information.
What is CVE-2019-14356?
The vulnerability in the OLED display of Coldcard MK1 and MK2 devices enables attackers to exploit power consumption during display cycles to recover sensitive data like PIN and BIP39 mnemonic.
The Impact of CVE-2019-14356
Technical Details of CVE-2019-14356
Coldcard MK1 and MK2 devices are affected by a side channel vulnerability in the row-based OLED display.
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Steps to address and prevent the vulnerability.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates