Logitech

First CVE: Apr 12, 2022Active for: 4 years
6
CVEs Published
More CVEs Published than 18% of tracked CNAs
3.0
Avg CVEs / Year
More Avg CVEs / Year than 19% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Logitech as a CNA, 83.3% affect products that Logitech develops as a vendor.

83.3%
16.7%
Self-reported: 5Third-party: 1

Of all the CVEs published that affect products developed by Logitech, 13.9% are self-published by Logitech as a CNA.

13.9%
86.1%
Self-published: 5Published by other CNAs: 31

Trends Over Time

The number and severity of CVEs published by Logitech over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 12, 2022
4 years ago
Most Recent CVE
Sep 10, 2024
681 days ago

Top CVEs

All CVEs published by Logitech as a CNA, regardless of affected vendor or product.

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF attacks during authentication and
May 3, 20228.826NONO
Improper Control of Dynamically-Managed Code Resources vulnerability in Logitech Logi Tune on MacOS allows Local Code Inclusion.
Mar 15, 20249.825NONO
Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code via ins
Sep 10, 20247.822NONO
Logitech Options+ on MacOS prior 1.72 allows a local attacker to inject dynamic library within Options+ runtime and abuse permissions granted by the user to Options+ such as Camera
Aug 25, 20245.518NONO
There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Logitech Sync for Windows prior to 2.4.574. Successful exploitation of these vulnerabilities may escal
Apr 12, 20227.018NONO
Unquoted Search Path or Element vulnerability in Logitech MEVO WEBCAM APP on Windows allows Local Execution of Code.
Apr 23, 20244.416NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA6 CVEs
Severity distribution among all CVEs352,101 CVEs
MediumHighCritical
Attack Vector
Local4 (66.7%)
Network2 (33.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (83.3%)
High1 (16.7%)
Unknown0 (0.0%)
User Interaction
None5 (83.3%)
Unknown0 (0.0%)
Required1 (16.7%)
Privileges Required
Low4 (66.7%)
High0 (0.0%)
None2 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Logitech as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Logitech as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs