Thisaay Lazy Mouse vulnerabilities
3 known vulnerabilities affecting thisaay/lazy_mouse.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2022-45481P2CRITICALCVSS 9.8≤ 2.0.12022-12-05
CVE-2022-45481 [CRITICAL] CWE-306 CVE-2022-45481: The default configuration of Lazy Mouse does not require a password, allowing remote unauthenticated
The default configuration of Lazy Mouse does not require a password, allowing remote unauthenticated users to execute arbitrary code with no prior authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd
CVE-2022-45482P2CRITICALCVSS 9.8≤ 2.0.12022-12-02
CVE-2022-45482 [CRITICAL] CWE-521 CVE-2022-45482: Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing
Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execute arbitrary commands. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd
CVE-2022-45483P4MEDIUMCVSS 5.9≤ 2.0.12022-12-02
CVE-2022-45483 [MEDIUM] CWE-319 CVE-2022-45483: Lazy Mouse allows an attacker (in a man in the middle position between the server and a connected de
Lazy Mouse allows an attacker (in a man in the middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd