VulnerabilityModified
CVE-2022-35860
Missing AES encryption in Corsair K63 Wireless 3.1.3 allows physically proximate attackers to inject and sniff keystrokes via 2.4 GHz radio transmissions.
MEDIUM 6.8EPSS 0.22%
Does this matter?
Lower severity and a low EPSS score (0.22%). Track it; it rarely justifies an emergency change on its own.
Description
Missing AES encryption in Corsair K63 Wireless 3.1.3 allows physically proximate attackers to inject and sniff keystrokes via 2.4 GHz radio transmissions.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 0.22% probability · 13th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-311
- Affected
- corsair/k63 firmware
- Source
- cve@mitre.org
References
- http://kth.diva-portal.org/smash/get/diva2:1701492/FULLTEXT01.pdfExploit, Third Party Advisory
- http://kth.diva-portal.org/smash/record.jsf?pid=diva2%3A1701492&dswid=-3616Third Party Advisory
- https://www.corsair.com/us/en/Categories/Products/Gaming-Keyboards/Wireless-Keyboards/K63-Wireless-Mechanical-Gaming-Keyboard-%E2%80%94-Blue-LED-%E2%80%94-CHERRY%C2%AE-MX-Red/p/CH-9145030-NAProduct, Vendor Advisory
- http://kth.diva-portal.org/smash/get/diva2:1701492/FULLTEXT01.pdfExploit, Third Party Advisory
- http://kth.diva-portal.org/smash/record.jsf?pid=diva2%3A1701492&dswid=-3616Third Party Advisory
- https://www.corsair.com/us/en/Categories/Products/Gaming-Keyboards/Wireless-Keyboards/K63-Wireless-Mechanical-Gaming-Keyboard-%E2%80%94-Blue-LED-%E2%80%94-CHERRY%C2%AE-MX-Red/p/CH-9145030-NAProduct, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.