Home Embedded Vulns General Vulns

CVE-2020-6861

MEDIUM 5.5

Our Analysis: Environment Specific

Our model has classified this vulnerability as relevant to Environment Specific Systems, helping your team prioritize efforts effectively.

Published Date May 6, 2020
Last Modified November 21, 2024
CVSS Vector Not Available

Description

A flawed protocol design in the Ledger Monero app before 1.5.1 for Ledger Nano and Ledger S devices allows a local attacker to extract the master spending key by sending crafted messages to this app selected on a PIN-entered Ledger connected to a host PC.

Potentially Affected Vendors