VulnerabilityModified
CVE-2019-13054
The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection.
MEDIUM 6.5EPSS 0.85%
Does this matter?
Lower severity and a low EPSS score (0.85%). Track it; it rarely justifies an emergency change on its own.
Description
The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Windows, any text may be injected by using ALT+NUMPAD input to bypass the restriction on the characters A through Z.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.85% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- logitech/r500 firmware
- Source
- cve@mitre.org
References
- https://twitter.com/mame82/status/1143093313924452353Exploit, Third Party Advisory
- https://twitter.com/mame82/status/1143093313924452353Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.