216.73.216.6

CVE-2023-7345

· Published 19/05/2026 22:16 · Modified 20/05/2026 14:16

Labels: CVE-2023-7345 2026-05-19CVE-2023-7345CWE-704[email protected]

Essential information

Published
19/05/2026 22:16
Modified
20/05/2026 14:16
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability that allows attackers to manipulate EIP-712 typed data messages by exploiting incorrect hexadecimal field parsing when values contain an odd number of characters. Attackers can obtain signatures on truncated or misinterpreted message values to authorize unintended blockchain transactions, such as asset transfers at incorrect amounts.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
ledgerhq / hw-app-eth cpe:2.3:a:ledgerhq:hw-app-eth:<6.34.7:*:*:*:*:*:*:*

References