CVE-2022-3365 Details
Description
Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the user does not set a password, the Remote Mouse Server by Emote Interactive can be abused by attackers to inject OS commands over theproduct's custom control protocol. A Metasploit module was written and tested against version 4.110, the current version when this CVE was reserved.
A vulnerability in the Remote Mouse Server by Emote Interactive allows attackers to inject operating system commands via the application's custom control protocol. This issue arises from the use of a simple substitution cipher sent in cleartext, combined with the reliance on a default password when users do not set one. The vulnerability has been confirmed in version 4.110, which was the latest release at the time this CVE was filed.
Users are advised to update to Remote Mouse Server version 4.502 or later, as this version addresses the vulnerability by removing the default password and implementing other security measures.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 28, 2025CISA-ADP
Assessed Jan 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/rapid7/metasploit-framework/pull/17067 | [email protected] | ExploitIssue TrackingTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-327 | Use of a Broken or Risky Cryptographic Algorithm | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Emote Interactive Remote Mouse Server | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 28, 2025 | CVE Modified | CISA-ADP |
| Jan 28, 2025 | New CVE Received | [email protected] |
Volerion