Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hpg2-wgv6-vgm5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A flawed protocol design in the Ledger Monero app before 1.5.1 for Ledger Nano and Ledger S devices allows a local attacker to extract the master spending key by sending crafted messages to this app selected on a PIN-entered Ledger connected to a host PC.

A flawed protocol design in the Ledger Monero app before 1.5.1 for Ledger Nano and Ledger S devices allows a local attacker to extract the master spending key by sending crafted messages to this app selected on a PIN-entered Ledger connected to a host PC.

EPSS

Процентиль: 69%
0.00591
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.5
nvd
почти 6 лет назад

A flawed protocol design in the Ledger Monero app before 1.5.1 for Ledger Nano and Ledger S devices allows a local attacker to extract the master spending key by sending crafted messages to this app selected on a PIN-entered Ledger connected to a host PC.

EPSS

Процентиль: 69%
0.00591
Низкий

Дефекты

CWE-200