First published: Mon Jan 29 2007(Updated: )
The virtual keyboard implementation in GlobeTrotter Mobility Manager changes the color of a key as it is pressed, which allows local users to capture arbitrary keystrokes, such as for passwords, by shoulder surfing or grabbing periodic screenshots.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GlobeTrotter Mobility Manager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6953 is considered a medium severity vulnerability due to the potential for local users to capture sensitive information.
To fix CVE-2006-6953, update GlobeTrotter Mobility Manager to a version where this issue is addressed or consider disabling the virtual keyboard feature.
CVE-2006-6953 enables shoulder surfing attacks, allowing attackers to capture keystrokes visually.
Local users of the GlobeTrotter Mobility Manager software are affected by CVE-2006-6953.
Yes, CVE-2006-6953 can lead to credential theft as sensitive information such as passwords may be captured.