PT-2022-27827 · G810-Led · G810-Led
Carnil
·
Published
2022-11-30
·
Updated
2025-04-24
·
CVE-2022-46338
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
g810-led version 0.4.2
Description
The issue allows any process on the system to read traffic from keyboards, including sensitive data, due to a udev rule that makes supported device nodes world-readable and writable. This affects a LED configuration tool for Logitech Gx10 keyboards.
Recommendations
For g810-led version 0.4.2, consider restricting access to the device nodes to prevent unauthorized processes from reading keyboard traffic until a patch is available. As a temporary workaround, review and modify the udev rule to limit read and write access to the device nodes.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
G810-Led