Vulnerability Name: | CVE-2019-18201 (CCN-170104) | ||||||||||||
Assigned: | 2019-10-23 | ||||||||||||
Published: | 2019-10-23 | ||||||||||||
Updated: | 2021-07-21 | ||||||||||||
Summary: | An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, an attacker is able to eavesdrop on sensitive data such as passwords. | ||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) 6.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:R)
5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:R)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-311 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-18201 Source: MISC Type: Exploit, Third Party Advisory, VDB Entry http://packetstormsecurity.com/files/154955/Fujitsu-Wireless-Keyboard-Set-LX390-Missing-Encryption.html Source: XF Type: UNKNOWN fujitsu-cve201918201-info-disc(170104) Source: CCN Type: Packet Storm Security [10-23-2019] Fujitsu Wireless Keyboard Set LX390 Missing Encryption Source: CCN Type: Fujitsu Web site Fujitsu Wireless Keyboard Set LX390 Source: MISC Type: Exploit, Third Party Advisory https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-010.txt Source: MISC Type: Third Party Advisory https://www.syss.de/pentest-blog/2019/syss-2019-009-syss-2019-010-und-syss-2019-011-schwachstellen-in-weiterer-funktastatur-mit-sicherer-24-ghz-technologie/ | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
BACK |