PT-2009-3973 · Aten · Aten Kh1516I Ip Kvm Switch+1
Published
2009-05-27
·
Updated
2018-10-10
·
CVE-2009-1474
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
ATEN KH1516i IP KVM switch version 1.0.063
ATEN KN9116 IP KVM switch version 1.1.104
Description:
The issue concerns the lack of encryption for mouse events and the insecure handling of session cookies in https sessions. This makes it easier for man-in-the-middle attackers to inject network traffic and perform mouse operations on connected machines. Additionally, remote attackers can capture session cookies by intercepting their transmission within an http session.
Recommendations:
For ATEN KH1516i IP KVM switch version 1.0.063, consider disabling the mouse event transmission feature until a patch is available that properly encrypts these events.
For ATEN KN9116 IP KVM switch version 1.1.104, restrict access to the https session cookie by setting the secure flag, and avoid using http sessions to minimize the risk of cookie capture.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aten Kh1516I Ip Kvm Switch
Aten Kn9116 Ip Kvm Switch