CVE Vulnerabilities

CVE-2019-9835

Published: Mar 15, 2019 | Modified: Aug 24, 2020
CVSS 3.x
9.6
CRITICAL
Source:
NVD
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
5.8 MEDIUM
AV:A/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The receiver (aka bridge) component of Fujitsu Wireless Keyboard Set LX901 GK900 devices allows Keystroke Injection. This occurs because it accepts unencrypted 2.4 GHz packets, even though all legitimate communication uses AES encryption.

Affected Software

Name Vendor Start Version End Version
Lx901_firmware Fujitsu - (including) - (including)

References