CVE-2009-1474
Last modified
CVE-2009-1474 is a vulnerability of currently unknown severity. The ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 do not (1) encrypt mouse events, which makes it easier for man-in-the-middle attackers to perform mouse operations on machines connected to the switch by injecting network traffic; and do not (2) set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.. EPSS estimates a 1.68% chance of exploitation in the next 30 days.
Description
The ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 do not (1) encrypt mouse events, which makes it easier for man-in-the-middle attackers to perform mouse operations on machines connected to the switch by injecting network traffic; and do not (2) set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Aten | Kh1516i Ip Kvm Switch | 1.0.063 |
| Aten | Kn9116 Ip Kvm Switch | 1.1.104 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-1474?
How severe is CVE-2009-1474?
How do I fix CVE-2009-1474?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-1466Application Access Server (A-A-S) 2.0.48 stores (1) password…5.5
- CVE-2009-1467Multiple cross-site scripting (XSS) vulnerabilities in IceWa…
- CVE-2009-1468Multiple SQL injection vulnerabilities in the search form in…
- CVE-2009-1469CRLF injection vulnerability in the Forgot Password implemen…
- CVE-2009-1472The Java client program for the ATEN KH1516i IP KVM switch w…
- CVE-2009-1473The (1) Windows and (2) Java client programs for the ATEN KH…
- CVE-2009-1476Buffer overflow in lib/load_http.c in ippool in Darren Reed …
- CVE-2009-1477The https web interfaces on the ATEN KH1516i IP KVM switch w…
- CVE-2009-1478Multiple unspecified vulnerabilities in the DTrace ioctl han…
- CVE-2009-1479Directory traversal vulnerability in client/desktop/default.…
- CVE-2009-1480SQL injection vulnerability in index.php Pragyan CMS 2.6.4 a…
- CVE-2009-1481SQL injection vulnerability in action.asp in PuterJam's Blog…
Are you affected by CVE-2009-1474?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
