Potential impact:Unnecessary data input may occur.
Importance
:Medium
Impact scope:Industry-wide
Abstract description:
One vulnerability found:Attackers in the vicinity of system physics can use specialized devices to input (such as keys) the user's system using the Lenovo Ultraslim wireless keyboard and mouse receiver ).
Due to this vulnerability, valid users still encrypt their input through the wireless keyboard, while text-only Keys entered through the Lenovo Ultraslim wireless keyboard cannot be wirelessly read.
Solution:
Measures should be taken for self-protection:
Lenovo recommends using the Ultraslim wireless keyboard and mouse in areas with physical security. Lenovo is working hard to fix the firmware on the affected keyboard. This firmware can only be installed during manufacturing. Users who are worried about this problem and need immediate relief can contact the Lenovo Support Center (http://support.lenovo.com.cn/lenovo/wsi/contact.html), which will replace the affected keyboard and mouse with a wired keyboard and mouse.
This announcement will be updated when you can fix the firmware and we recommend that you contact the Lenovo Support Center. At that time, Lenovo will take the initiative to replace the affected keyboard with a new Ultraslim wireless keyboard and a receiver containing updated firmware. Lenovo is very grateful to the affected customers for their patience. The company will do its best to process all requests seriously and efficiently.
Product impact:
Part description |
FRU |
Part number |
Liteon SK-8861 2.4G KBD_GD_US |
00x000036 |
SD50M33721 |
Liteon ZTM600 2.4G mouse GD_WW |
00PH140 |
SM50M33720 |
Wireless Keyboard black (Silver drawing) English LVT8 |
01AH627 |
SD50K93072 25209175 |
Wireless Keyboard black (silver brushed) Malaysian English LVT8 |
01AH628 |
SD50K93080 25209176 |
Wireless Keyboard black (silver brushed) Traditional Chinese LVT8 |
01AH629 |
SD50K93084 25209177 |
Wireless Keyboard black (silver brushed) Thai LVT8 |
01AH630 |
SD50K93078 |
Wireless Keyboard black (silver brushed) Czech/Slovak LVT8 |
01AH631 |
SD50K93079 |
Wireless Keyboard black (Silver drawing) Indian English LVT8 |
01AH632 |
SD50K93116 |
Wireless Keyboard black (Silver drawing) Russian LVT8 |
01AH633 |
SD50K93113 |
Wireless Keyboard black (Silver drawing) English LVT8 |
01AH634 |
SD50K93109 25209182 |
Wireless Keyboard black (Silver drawing) Nordic language LVT8 |
01AH635 |
SD50K93094 25209183 |
Wireless Keyboard black (Silver drawing) Latin Spanish LVT8 |
01AH636 |
SD50K93095 25209184 |
Wireless Keyboard black (Silver drawing) Argentina Lata Spanish LVT8 |
01AH637 |
SD50K93069 25209185 |
Wireless Keyboard black (silver brushed) Arabic LVT8 |
01AH638 |
SD50K93098 25209186 |
Wireless Keyboard black (Silver drawing) Swiss language LVT8 |
01AH639 |
SD50K93064 25209187 |
Wireless Keyboard black (silver brushed) German LVT8 |
01AH640 |
SD50K93099 25209188 |
Wireless Keyboard black (silver brushed) Turkish LVT8 |
01AH641 |
SD50K93107 25209189 |
Wireless Keyboard black (silver brushed) Spanish LVT8 |
01ah133 |
SD50K93061 25209190 |
Wireless Keyboard black (silver brushed) Cantonese LVT8 |
01AH643 |
SD50K93091 25209191 |
Wireless Keyboard black (silver brushed) Italian LVT8 |
01AH644 |
SD50K93111 25209192 |
Wireless Keyboard black (silver brushed) Hebrew LVT8 |
01AH645 |
SD50K93092 25209193 |
Wireless Keyboard black (Silver drawing) French LVT8 |
01AH646 |
SD50K93060 25209194 |
Wireless Keyboard black (silver brushed) Greek LVT8 |
01AH647 |
SD50K93062 25209195 |
Wireless Keyboard black (silver brushed) Hungarian LVT8 |
01AH648 |
SD50K93076 25209196 |
Wireless Keyboard, Black (Silver drawing), Bulgaria LVT8 |
01AH649 |
SD50K93102 25209197 |
Wireless Keyboard black (silver brushed) Korean LVT8 |
01AH650 |
SD50K93082 25209198 |
Wireless Keyboard black (Silver drawing) Japanese LVT8 |
01AH651 |
SD50K93112 25209199 |
Wireless Keyboard black (silver brushed) Canadian English/French LVT8 |
01AH652 |
SD50K93075 25209200 |
Wireless Keyboard black (silver brushed) Portuguese LVT8 |
01AH653 |
SD50K93103 25209201 |
Wireless Keyboard black (Silver drawing) Belgian English LVT8 |
01AH654 |
SD50K93081 25209202 |
Wireless Keyboard black (Silver drawing) USI English LVT8 (Netherlands) |
01AH655 |
SD50K93065 25209203 |
Silver brushed 2.4G keyboard (English)-Black |
00UW407 |
SD50K02047 |
Wireless Mouse Black |
01AH700 |
SM50K93074 25203464 |
Wireless Mouse black no battery |
00UW408 |
SM50K02048 25203465 |
Wireless Mouse black Malaysian |
01AH701 |
SM50K93114 25203466 |
Wireless Mouse black Japanese |
01AH702 |
SM50K93110 25205773 |
Thanks:
Lenovo would like to thank Marc Newlin from the Bastille Threat Research team.
Other information and references:
Cve id: CVE-2016-6257
Revision history:
Version: 1.0
Date: January 1, July 26, 2016
Description: initial version.