PT-2025-1362 · Emote Interactive · Remote Mouse Server
H00Die
·
Published
2025-01-28
·
Updated
2025-01-28
·
CVE-2022-3365
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Remote Mouse Server by Emote Interactive version 4.110
Description
The issue arises due to the product's reliance on a trivial substitution cipher sent in cleartext and its use of a default password when no password is set by the user. This allows attackers to inject OS commands over the product's custom control protocol.
Recommendations
Remote Mouse Server by Emote Interactive version 4.110: Update the software to a version that does not rely on trivial substitution ciphers and default passwords, or set a strong custom password to mitigate the risk. As a temporary workaround, consider restricting access to the custom control protocol until a patch is available.
Exploit
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Remote Mouse Server