๐Ÿ” CVE Alert

CVE-2023-7345

MEDIUM 6.5

Ledger Live hw-app-eth EIP-712 Message Parsing Integer Truncation

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
8th

Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability that allows attackers to manipulate EIP-712 typed data messages by exploiting incorrect hexadecimal field parsing when values contain an odd number of characters. Attackers can obtain signatures on truncated or misinterpreted message values to authorize unintended blockchain transactions, such as asset transfers at incorrect amounts.

CWE CWE-704
Vendor ledger
Product ledgerhq/hw-app-eth
Published May 19, 2026
Last Updated May 20, 2026
Stay Ahead of the Next One

Get instant alerts for ledger ledgerhq/hw-app-eth

Be the first to know when new medium vulnerabilities affecting ledger ledgerhq/hw-app-eth are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

Ledger / ledgerhq/hw-app-eth
0 < 6.34.7
Ledger / Ledger Live
0 < 2.70.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
donjon.ledger.com: https://donjon.ledger.com/lsb/020/ vulncheck.com: https://www.vulncheck.com/advisories/ledger-live-hw-app-eth-eip-712-message-parsing-integer-truncation

Credits

Ian Fisher VulnCheck