SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-6257

The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to…

MEDIUM 6.5EPSS 1.02%

Does this matter?

Lower severity and a low EPSS score (1.02%). Track it; it rarely justifies an emergency change on its own.

Description

The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject encrypted keyboard input into the system by leveraging proximity to the dongle, aka a "KeyJack injection attack."

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
1.02% probability · 62th percentile
CISA KEV
Not listed
Weakness
CWE-310
Affected
amazonbasics/firmware · dell/km714 firmware · dell/km632 firmware · logitech/unifying firmware · lenovo/ultraslim firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.