CVE Vulnerabilities

CVE-2019-12504

Cleartext Transmission of Sensitive Information

Published: Jun 07, 2019 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
8.3 HIGH
AV:A/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Due to unencrypted and unauthenticated data communication, the wireless presenter Inateck WP2002 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victims computer system, e.g., to install malware when the target system is unattended. In this way, an attacker can remotely take control over the victims computer that is operated with an affected receiver of this device.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Wp2002_firmware Inateck - (including) - (including)

Potential Mitigations

References