The vulnerability could be used to mount a supply chain attack.
It is recommended you update your Ledger to the latest version.
https://saleemrashid.com/2018/03/20/breaking-ledger-security-model/
This is Ledger's official response:
https://www.ledger.fr/2018/03/20/firmware-1-4-deep-dive-security-fixes/
Thanks to the link to Ledger's official response, it gives a lot of useful information. I have now updated the Ledger to the laters version, even though the update itself didn't run smoothly, a problem of drivers on window had stalled eveything for hours.