PT-2019-12833 · Inateck · Inateck Wp1001
Publicado
2019-06-07
·
Atualizado
2020-08-24
·
CVE-2019-12505
CVSS v3.1
8.8
Alta
| Vetor | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Inateck WP1001 version 1.3C
Description
The issue allows for keystroke injection attacks due to unencrypted and unauthenticated data communication. This enables an attacker to send arbitrary keystrokes to a victim's computer system, potentially installing malware on an unattended target system. As a result, an attacker can remotely take control of the victim's computer that is operated with an affected receiver of this device.
Recommendations
For Inateck WP1001 version 1.3C, consider disabling the device until a patch or secure alternative is available to prevent keystroke injection attacks. Restrict access to sensitive systems and data when using the affected device to minimize the risk of exploitation.
Correção
Missing Authentication
Cleartext Transmission of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Inateck Wp1001