A flawed protocol design in the Ledger Monero app before 1.5.1 for Ledger Nano and Ledger S devices allows a local attacker to extract the master spending key by sending crafted messages to this app selected on a PIN-entered Ledger connected to a host PC.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-05-06T13:15:31
Updated: 2024-08-04T09:11:05.166Z
Reserved: 2020-01-13T00:00:00
Link: CVE-2020-6861
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-05-06T14:15:11.083
Modified: 2024-11-21T05:36:18.813
Link: CVE-2020-6861
Redhat
No data.