6.5

CVE-2016-6257

The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject encrypted keyboard input into the system by leveraging proximity to the dongle, aka a "KeyJack injection attack."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Amazonbasics ≫ Firmware Version -
   Amazonbasics ≫ Usb Dongle Version -
   Amazonbasics ≫ Wireless Keyboard Version -
Dell ≫ Km714 Firmware Version <= 012.005.00028
   Dell ≫ Km714 Dongle Version -
   Dell ≫ Km714 Wireless Keyboard Version -
Dell ≫ Km632 Firmware Version -
   Dell ≫ Km632 Dongle Version -
   Dell ≫ Km632 Wireless Keyboard Version -
Logitech ≫ Unifying Firmware Version <= 012.005.00028
   Logitech ≫ Unifying Dongle Version -
Logitech ≫ Unifying Firmware Version <= 024.003.00027
   Logitech ≫ Unifying Dongle Version -
Lenovo ≫ Ultraslim Firmware Version -
   Lenovo ≫ Ultraslim Dongle Version -
   Lenovo ≫ Ultraslim Wireless Keyboard Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.02% 0.59
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
NIST 3.3 6.5 2.9
AV:A/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.securityfocus.com/bid/92179
Third Party Advisory
VDB Entry
https://github.com/BastilleResearch/keyjack/blob/master/doc/advisories/bastille-13.lenovo-ultraslim.public.txt
Third Party Advisory
https://support.lenovo.com/product_security/len_7267
Vendor Advisory
https://www.bastille.net/research/vulnerabilities/keyjack
Third Party Advisory