Vulnerability Details CVE-2021-41096
Rucky is a USB HID Rubber Ducky Launch Pad for Android. Versions 2.2 and earlier for release builds and versions 425 and earlier for nightly builds suffer from use of a weak cryptographic algorithm (RSA/ECB/PKCS1Padding). The issue will be patched in v2.3 for release builds and 426 onwards for nightly builds. As a workaround, one may disable an advance security feature if not required.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 36.0%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2021-41096
-
cpe:2.3:a:rucky_project:rucky:1.0
-
cpe:2.3:a:rucky_project:rucky:1.1
-
cpe:2.3:a:rucky_project:rucky:1.2
-
cpe:2.3:a:rucky_project:rucky:1.3
-
cpe:2.3:a:rucky_project:rucky:1.4
-
cpe:2.3:a:rucky_project:rucky:1.5
-
cpe:2.3:a:rucky_project:rucky:1.6
-
cpe:2.3:a:rucky_project:rucky:1.7
-
cpe:2.3:a:rucky_project:rucky:1.8
-
cpe:2.3:a:rucky_project:rucky:1.9
-
cpe:2.3:a:rucky_project:rucky:2.0
-
cpe:2.3:a:rucky_project:rucky:2.1
-
cpe:2.3:a:rucky_project:rucky:2.2