CVE-2020-14199

MEDIUM

Trezor Model T Firmware < 2.3.1 and Trezor One Firmware < 1.9.1 - Improper Verification of Cryptographic Signature

Title source: llm
STIX 2.1

Description

BIP-143 in the Bitcoin protocol specification mishandles the signing of a Segwit transaction, which allows attackers to trick a user into making two signatures in certain cases, potentially leading to a huge transaction fee. NOTE: this affects all hardware wallets. It was fixed in 1.9.1 for the Trezor One and 2.3.1 for the Trezor Model T.

Scores

CVSS v3 6.5
EPSS 0.0085
EPSS Percentile 53.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-347
Status published
Products (2)
satoshilabs/trezor_model_t_firmware < 2.3.1
satoshilabs/trezor_one_firmware < 1.9.1
Published Jun 16, 2020
Tracked Since Feb 18, 2026