VulnerabilityModified
CVE-2019-18199
Because of the lack of proper encryption of 2.4 GHz communication, and because of password-based authentication, they are vulnerable to replay attacks.
MEDIUM 6.6EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, and because of password-based authentication, they are vulnerable to replay attacks.
- CVSS 3.1
- 6.6 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- fujitsu/lx390 firmware
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/154954/Fujitsu-Wireless-Keyboard-Set-LX390-Replay-Attacks.htmlExploit, Third Party Advisory, VDB Entry
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-009.txtExploit, Third Party Advisory
- https://www.syss.de/pentest-blog/2019/syss-2019-009-syss-2019-010-und-syss-2019-011-schwachstellen-in-weiterer-funktastatur-mit-sicherer-24-ghz-technologie/Third Party Advisory
- http://packetstormsecurity.com/files/154954/Fujitsu-Wireless-Keyboard-Set-LX390-Replay-Attacks.htmlExploit, Third Party Advisory, VDB Entry
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-009.txtExploit, Third Party Advisory
- https://www.syss.de/pentest-blog/2019/syss-2019-009-syss-2019-010-und-syss-2019-011-schwachstellen-in-weiterer-funktastatur-mit-sicherer-24-ghz-technologie/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.