Ledger manufactures hardware security modules and wallet applications, including the widely deployed Nano S and Nano X devices alongside its Ledger Live companion software, presenting a focused but security-critical attack surface for cryptocurrency asset custody. Vulnerabilities affecting this vendor center on cryptographic and data-integrity issues, including insufficient verification of data authenticity, observable discrepancies in security operations, and reliance on broken or risky cryptographic algorithms, reflecting the authentication and key-derivation demands of hardware wallet implementations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ledger over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-12119HIGH Ledger Live before 2.7.0 does not handle Bitcoin's Replace-By-Fee (RBF). It increases the user's balance with the value of an unconfirmed transaction as soon as it is received (bef | Jul 2, 2020 | 8.1 | 20 | NO | NO |
CVE-2020-6861MEDIUM A flawed protocol design in the Ledger Monero app before 1.5.1 for Ledger Nano and Ledger S devices allows a local attacker to extract the master spending key by sending crafted me | May 6, 2020 | 5.5 | 17 | NO | NO |
On Ledger Nano S and Nano X devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illumin | Aug 10, 2019 | 2.4 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ledger.
Media articles that mention a CVE ID that affects a product developed by Ledger — matched by CVE ID, not by vendor name.