2.1
CVSSv2

CVE-2020-6861

Published: 06/05/2020 Updated: 21/07/2021
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A flawed protocol design in the Ledger Monero app prior to 1.5.1 for Ledger Nano and Ledger S devices allows a local malicious user to extract the master spending key by sending crafted messages to this app selected on a PIN-entered Ledger connected to a host PC.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ledger monero

Github Repositories

PoC repository for CVE-2020-6861: Ledger Monero App Spend key Extraction

CVE-2020-6861: Ledger Monero App Spend key Extraction PoC repository for article: deadcodeme/blog/2020/04/25/Ledger-Monero-app-spend-key-extractionhtml