CVE-2016-6257
The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject encrypted keyboard input into the system by leveraging proximity to the dongle, aka a "KeyJack injection attack."
Published:Aug 2, 2016
Last Modified:Apr 12, 2025
EPS:Aug 2, 2016
EPSS Score:0.01034
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Amazonbasics
Product
Firmware
Amazonbasics
Firmware
Vendor
Amazonbasics
Product
Usb Dongle
Amazonbasics
Usb Dongle
Vendor
Amazonbasics
Product
Wireless Keyboard
Amazonbasics
Wireless Keyboard
Vendor
Dell
Product
Km632 Dongle
Dell
Km632 Dongle
Vendor
Dell
Product
Km632 Firmware
Dell
Km632 Firmware
Vendor
Dell
Product
Km632 Wireless Keyboard
Dell
Km632 Wireless Keyboard
Vendor
Dell
Product
Km714 Dongle
Dell
Km714 Dongle
Vendor
Dell
Product
Km714 Firmware
Dell
Km714 Firmware
Vendor
Dell
Product
Km714 Wireless Keyboard
Dell
Km714 Wireless Keyboard
Vendor
Lenovo
Product
Ultraslim Dongle
Lenovo
Ultraslim Dongle
Vendor
Lenovo
Product
Ultraslim Firmware
Lenovo
Ultraslim Firmware
Vendor
Lenovo
Product
Ultraslim Wireless Keyboard
Lenovo
Ultraslim Wireless Keyboard
Vendor
Logitech
Product
Unifying Dongle
Logitech
Unifying Dongle
Vendor
Logitech
Product
Unifying Firmware
Logitech
Unifying Firmware
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
