CVE-2023-7345
Ledger Live hw-app-eth EIP-712 Message Parsing Integer Truncation
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
8th
Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability that allows attackers to manipulate EIP-712 typed data messages by exploiting incorrect hexadecimal field parsing when values contain an odd number of characters. Attackers can obtain signatures on truncated or misinterpreted message values to authorize unintended blockchain transactions, such as asset transfers at incorrect amounts.
| CWE | CWE-704 |
| Vendor | ledger |
| Product | ledgerhq/hw-app-eth |
| Published | May 19, 2026 |
| Last Updated | May 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for ledger ledgerhq/hw-app-eth
Be the first to know when new medium vulnerabilities affecting ledger ledgerhq/hw-app-eth are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Affected Versions
Ledger / ledgerhq/hw-app-eth
0 < 6.34.7
Ledger / Ledger Live
0 < 2.70.0
References
Credits
Ian Fisher VulnCheck