← Back

CVE-2016-6257

nvd nist
Published: Aug 2, 2016Modified: May 6, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject encrypted keyboard input into the system by leveraging proximity to the dongle, aka a "KeyJack injection attack."

Affected (6)

Show all products
1 product
Firmware
2 products
Km714 Firmware
Km632 Firmware
1 product
Unifying Firmware
1 product
Ultraslim Firmware
Configuration A
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Amazonbasics
Usb Dongle
All versions
Amazonbasics
Wireless Keyboard
All versions
Configuration B
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Up to 012.005.00028
Running on/withPlatform Versions
Dell
Km714 Dongle
All versions
Dell
Km714 Wireless Keyboard
All versions
Configuration C
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dell
Km632 Dongle
All versions
Dell
Km632 Wireless Keyboard
All versions
Configuration D
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Logitech
Up to 012.005.00028
Up to 024.003.00027
Running on/withPlatform Versions
Logitech
Unifying Dongle
All versions
Configuration E
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Lenovo
Ultraslim Dongle
All versions
Lenovo
Ultraslim Wireless Keyboard
All versions

Related CWEs

References (8)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.