CVE-2019-13055

MEDIUM

Logitech Unifying Receiver Firmware - Exposure of Sensitive Information via AES Key Dump

Title source: llm
STIX 2.1

Description

Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Frequency transmissions, as demonstrated by an attack against a Logitech K360 keyboard.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.youtube.com/watch?v=5z_PEZ5PyeA

Scores

CVSS v3 6.5
EPSS 0.0103
EPSS Percentile 59.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
logitech/k360_firmware
logitech/unifying_receiver_firmware
Published Jun 29, 2019
Tracked Since Feb 18, 2026