Vulnerabilities > Ledger

DATE CVE VULNERABILITY TITLE RISK
2020-07-02 CVE-2020-12119 Insufficient Verification of Data Authenticity vulnerability in Ledger Live
Ledger Live before 2.7.0 does not handle Bitcoin's Replace-By-Fee (RBF).
network
low complexity
ledger CWE-345
8.1
2020-05-06 CVE-2020-6861 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Ledger Monero
A flawed protocol design in the Ledger Monero app before 1.5.1 for Ledger Nano and Ledger S devices allows a local attacker to extract the master spending key by sending crafted messages to this app selected on a PIN-entered Ledger connected to a host PC.
local
low complexity
ledger CWE-327
5.5
2019-08-10 CVE-2019-14354 Information Exposure Through Discrepancy vulnerability in Ledger Nano S Firmware and Nano X Firmware
On Ledger Nano S and Nano X devices, a side channel for the row-based OLED display was found.
low complexity
ledger CWE-203
2.4