CVE-2006-6953: Infoleak
The virtual keyboard implementation in GlobeTrotter Mobility Manager changes the color of a key as it is pressed, which allows local users to capture arbitrary keystrokes, such as for passwords, by shoulder surfing or grabbing periodic screenshots.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6953?
CVE-2006-6953 is considered a medium severity vulnerability due to the potential for local users to capture sensitive information.
How do I fix CVE-2006-6953?
To fix CVE-2006-6953, update GlobeTrotter Mobility Manager to a version where this issue is addressed or consider disabling the virtual keyboard feature.
What type of attack does CVE-2006-6953 enable?
CVE-2006-6953 enables shoulder surfing attacks, allowing attackers to capture keystrokes visually.
Who is affected by CVE-2006-6953?
Local users of the GlobeTrotter Mobility Manager software are affected by CVE-2006-6953.
Can CVE-2006-6953 lead to credential theft?
Yes, CVE-2006-6953 can lead to credential theft as sensitive information such as passwords may be captured.