The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject encrypted keyboard input into the system by leveraging proximity to the dongle, aka a "KeyJack injection attack."
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2016-08-02T14:00:00

Updated: 2024-08-06T01:22:20.922Z

Reserved: 2016-07-20T00:00:00

Link: CVE-2016-6257

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2016-08-02T14:59:04.490

Modified: 2021-04-22T21:21:17.033

Link: CVE-2016-6257

cve-icon Redhat

No data.