Logitech
First CVE: Apr 12, 2022Active for: 4 years
6
CVEs Published
More CVEs Published than 18% of tracked CNAs
3.0
Avg CVEs / Year
More Avg CVEs / Year than 19% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Logitech as a CNA, 83.3% affect products that Logitech develops as a vendor.
83.3%
16.7%
Self-reported: 5Third-party: 1
Of all the CVEs published that affect products developed by Logitech, 13.9% are self-published by Logitech as a CNA.
13.9%
86.1%
Self-published: 5Published by other CNAs: 31
Trends Over Time
The number and severity of CVEs published by Logitech over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 12, 2022
4 years ago
Most Recent CVE
Sep 10, 2024
681 days ago
Top CVEs
All CVEs published by Logitech as a CNA, regardless of affected vendor or product.
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0916HIGH An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF attacks during authentication and | May 3, 2022 | 8.8 | 26 | NO | NO |
CVE-2024-2537CRITICAL Improper Control of Dynamically-Managed Code Resources vulnerability in Logitech Logi Tune on MacOS allows Local Code Inclusion. | Mar 15, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-8258HIGH Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code via ins | Sep 10, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-8011MEDIUM Logitech Options+ on MacOS prior 1.72 allows a local attacker to inject dynamic library within Options+ runtime and abuse permissions granted by the user to Options+ such as Camera | Aug 25, 2024 | 5.5 | 18 | NO | NO |
CVE-2022-0915HIGH There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Logitech Sync for Windows prior to 2.4.574. Successful exploitation of these vulnerabilities may escal | Apr 12, 2022 | 7.0 | 18 | NO | NO |
CVE-2024-4031MEDIUM Unquoted Search Path or Element vulnerability in Logitech MEVO WEBCAM APP on Windows allows Local Execution of Code. | Apr 23, 2024 | 4.4 | 16 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA6 CVEs
33%
50%
17%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (66.7%)
Network2 (33.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (83.3%)
High1 (16.7%)
Unknown0 (0.0%)
User Interaction
None5 (83.3%)
Unknown0 (0.0%)
Required1 (16.7%)
Privileges Required
Low4 (66.7%)
High0 (0.0%)
None2 (33.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Logitech as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Logitech as a CNA — matched by CVE ID, not by organization name.