Vulnerabilities
Products Security index
Vulnerabilities
CVE-2023-7346
Ledger Bitcoin App 2.1.0 Address Derivation Error via Miniscript
CVE-2023-7345
Ledger Live hw-app-eth EIP-712 Message Parsing Integer Truncation
CVE-2025-15645
Ledger Nano X, Flex, Stax MCU Firmware Update Denial of Service
CVE-2020-12119
Ledger Live before 2.7.0 does not handle Bitcoin's Replace-By-Fee (RBF). It increases the user's balance with the value of an unconfirmed transaction as soon as it is received (before the transaction is confirmed) and does not decrease the balance when it is canceled. As a result, users are exposed to basic double spending attacks, amplified double spending attacks, and DoS attacks without user consent.
CVE-2020-6861
A flawed protocol design in the Ledger Monero app before 1.5.1 for Ledger Nano and Ledger S devices allows a local attacker to extract the master spending key by sending crafted messages to this app selected on a PIN-entered Ledger connected to a host PC.
