cbcvebase.
CVE-2022-46338
published 2022-11-30

CVE-2022-46338: g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable and writable…

PriorityP430medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.66%
48.0th percentile
g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable and writable, allowing any process on the system to read traffic from keyboards, including sensitive data.

Affected

7 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiang810-led< g810-led 0.4.2-3 (bookworm)g810-led 0.4.2-3 (bookworm)
g810-led_projectg810-led
g810-led_projectg810-led>= 0 < 0.4.2-1+deb11u10.4.2-1+deb11u1
g810-led_projectg810-led>= 0 < 0.4.2-30.4.2-3
g810-led_projectg810-led>= 0 < 0.4.2-30.4.2-3
g810-led_projectg810-led>= 0 < 0.4.2-30.4.2-3

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.