Overview
Wireless keyboard and mouse devices from multiple vendors use proprietary wireless protocols that are not properly secured.
Description
CWE-311: Missing Encryption of Sensitive Data Multiple wireless input devices (keyboard and mouse) use a proprietary wireless protocol on the 2.4 GHz ISM band that lacks proper encryption. An attacker within wireless transmission range can inject keystrokes or read keystroke data, or cause the victim's device to pair with a new input device. Wireless range on these models varies but is typically a few meters within a home. |
Impact
An attacker within wireless transmission range can inject keystrokes on the victim's device, or cause the victim's device to pair with a new input device. |
Solution
Update device firmware |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 2.9 | AV:A/AC:M/Au:N/C:N/I:P/A:N |
Temporal | 2.6 | E:POC/RL:U/RC:C |
Environmental | 1.9 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Marc Newlin of Bastille Threat Research Team for reporting this vulnerability.
This document was written by Garret Wassermann.
Other Information
CVE IDs: | None |
Date Public: | 2016-02-23 |
Date First Published: | 2016-02-24 |
Date Last Updated: | 2016-03-01 22:12 UTC |
Document Revision: | 31 |