PT-2016-6808 · Lenovo · Lenovo Ultraslim Dongles

Marc Newlin

·

Published

2016-08-02

·

Updated

2021-04-22

·

CVE-2016-6257

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Lenovo Ultraslim dongles (affected versions not specified)
Description The issue concerns the firmware in Lenovo Ultraslim dongles, which does not properly enforce incrementing AES counters. This allows remote attackers to inject encrypted keyboard input into the system by leveraging proximity to the dongle, a type of attack known as a "KeyJack injection attack."
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-6257

Affected Products

Lenovo Ultraslim Dongles