CVE-2022-3218
19.09.2022, 17:15
Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which can result in remote code execution.Enginsight
Vendor | Product | Version |
---|---|---|
necta | wifi_mouse_server | 1.7.8.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-603 - Use of Client-Side AuthenticationA client/server product performs authentication within client code but not in server code, allowing server-side authentication to be bypassed via a modified client that omits the authentication check.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.
References