Description
The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject encrypted keyboard input into the system by leveraging proximity to the dongle, aka a "KeyJack injection attack."
Published: 2016-08-02
Score: 6.5 Medium
EPSS: 1.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2016-7187 The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject encrypted keyboard input into the system by leveraging proximity to the dongle, aka a "KeyJack injection attack."
History

No history.

Subscriptions

Amazonbasics Firmware Usb Dongle Wireless Keyboard
Dell Km632 Dongle Km632 Firmware Km632 Wireless Keyboard Km714 Dongle Km714 Firmware Km714 Wireless Keyboard
Lenovo Ultraslim Dongle Ultraslim Firmware Ultraslim Wireless Keyboard
Logitech Unifying Dongle Unifying Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T01:22:20.922Z

Reserved: 2016-07-20T00:00:00.000Z

Link: CVE-2016-6257

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2016-08-02T14:59:04.490

Modified: 2025-04-12T10:46:40.837

Link: CVE-2016-6257

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses