VYPR

Lazy Mouse

by Lazy Mouse Project

CVEs (2)

  • CVE-2022-45482CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execute arbitrary commands. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

  • CVE-2022-45483MedDec 2, 2022
    risk 0.38cvss 5.9epss 0.00

    Lazy Mouse allows an attacker (in a man in the middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N