GSD-2022-1004952

    Dashboard / Vulnerabilities / GSD-2022-1004952

    GSD-2022-1004952

    Published: 5 Aug 2022Last Modified: 14 Mar 2023

    Summary: Logging of sensitive information in Wallet version Current version and possibly previous versions

    Details: In Slope Wallet, the current version and possibly previous versions the logging of sensitive information (including seed phrases) exist in the wallet software. This can be attacked via access to the logging data (which is reportedly sent in clear text across the Internet) and the logging server resulting in the disclosure of information including seed phrases used to generate cryptographic keys, allowing attackers access to private wallets and stealing funds (roughly 8000 wallets have been reportedly drained at this time). Users of Slope wallet should immediately and securely generate new wallet addresses in a different wallet software and transfer their funds to the new addresses.

    Affected packages

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GSD-2022-1004952 | CVE-DB