Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-12506


Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to install malware when the target system is unattended. In this way, an attacker can remotely take control over the victim's computer that is operated with an affected receiver of this device.


Published

2019-06-07T21:29:02.277

Last Modified

2024-11-21T04:22:59.737

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 8.8 (HIGH)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

6.5

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-306
    CWE-319

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System logitech r700_laser_presentation_remote_firmware wd802xm Yes
Operating System logitech r700_laser_presentation_remote_firmware wd904xm Yes
Hardware logitech r700_laser_presentation_remote - No

References