An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, an attacker is able to eavesdrop on sensitive data such as passwords.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/154955/Fujitsu-Wireless-Keyboard-Set-LX390-Missing-Encryption.html | Exploit Third Party Advisory VDB Entry |
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-010.txt | Exploit Third Party Advisory |
https://www.syss.de/pentest-blog/2019/syss-2019-009-syss-2019-010-und-syss-2019-011-schwachstellen-in-weiterer-funktastatur-mit-sicherer-24-ghz-technologie/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2019-10-24 15:15
Updated : 2021-07-21 11:39
NVD link : CVE-2019-18201
Mitre link : CVE-2019-18201
CVE.ORG link : CVE-2019-18201
JSON object : View
Products Affected
fujitsu
- lx390
- lx390_firmware
CWE
CWE-319
Cleartext Transmission of Sensitive Information