3.3
CVSSv2

CVE-2016-6257

Published: 02/08/2016 Updated: 22/04/2021
CVSS v2 Base Score: 3.3 | Impact Score: 2.9 | Exploitability Score: 6.5
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 294
Vector: AV:A/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote malicious users to inject encrypted keyboard input into the system by leveraging proximity to the dongle, aka a "KeyJack injection attack."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

amazonbasics firmware -

dell km714_firmware

dell km632_firmware -

logitech unifying_firmware

lenovo ultraslim_firmware -