CVE-2020-6861
MEDIUM 5.5EPSS 0.4%
A flawed protocol design in the Ledger Monero app before 1.5.1 for Ledger Nano and Ledger S devices allows a local attacker to extract the master spending key by sending crafted messages to this app selected on a PIN-entered Ledger connected to a host PC.
- CVSS v3.1
- 5.5 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - CVSS v2.0
- 2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 0.44% chance of exploitation in the next 30 days, 37th percentile
- Published
- 2020-05-06
- Updated
- 2024-08-04
Proof-of-concept exploits (2)
- https://deadcode.me/blog/2020/04/25/Ledger-Monero-app-spend-key-extraction.html
- ph4r05/ledger-app-monero-1.42-vuln4★ · 2020-04-27