Key Injection Vulnerability in Logitech R500 Presentation Clicker
CVE-2019-13054

6.5MEDIUM

Key Information:

Vendor

Logitech

Vendor
CVE Published:
29 June 2019

What is CVE-2019-13054?

The Logitech R500 presentation clicker has a vulnerability that allows attackers to deduce the AES encryption key, enabling keystroke injections. This can be exploited on Windows systems, where attackers can bypass character restrictions and inject arbitrary text using the ALT+NUMPAD input method. As a result, unauthorized commands may be executed remotely, posing significant security risks.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.