CVE-2020-14199
MEDIUMTrezor Model T Firmware < 2.3.1 and Trezor One Firmware < 1.9.1 - Improper Verification of Cryptographic Signature
Title source: llmDescription
BIP-143 in the Bitcoin protocol specification mishandles the signing of a Segwit transaction, which allows attackers to trick a user into making two signatures in certain cases, potentially leading to a huge transaction fee. NOTE: this affects all hardware wallets. It was fixed in 1.9.1 for the Trezor One and 2.3.1 for the Trezor Model T.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
https://blog.trezor.io/details-of-firmware-updates-for-trezor-one-version-1-9-1-and-trezor-model-t-version-2-3-1-1eba8f60f2dd
Scores
CVSS v3
6.5
EPSS
0.0085
EPSS Percentile
53.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Details
CWE
CWE-347
Status
published
Products (2)
satoshilabs/trezor_model_t_firmware
< 2.3.1
satoshilabs/trezor_one_firmware
< 1.9.1
Published
Jun 16, 2020
Tracked Since
Feb 18, 2026