Zurück zum Sicherheitsportal
Missing confirmation in the ECDHSessionKey call
Gemeldet auf November 26, 2023
The Trezor Safe 3 returns the ECDHSessionKey without requiring appropriate user interaction, resulting in the omission of address confirmation screens in the user interaction workflow.
This concerns only the SSH functionality in Trezor and was fixed in 2.6.4.
Gemeldet durch Mathias Herberts
Trezor Safe 3
Behobene Sicherheitslücken
Gemeldet durch Community. Untersucht. Gelöst. Weil deine Sicherheit nie optional ist.
- Inability to cancel certain flows on pre-production firmware31. Oktober 2025
- Donjon's Trezor Safe 3 evaluation12. November 2024
- XSS in Trezor Connect legacy versions7. Februar 2023
- Insufficient field size check in Protobuf12. Juli 2021
- XSS in Trezor Connect3. August 2020
- Missing path isolation check14. Juli 2020