Exposure of Sensitive System Information to an Unauthorized Control Sphere in Össur Logic - CVE-2024-53683
Published: January 8, 2025
Össur Logic
Detailed vulnerability description
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to the valid set of credentials in a .js file and a static token for communication are obtained from the decompiled IPA. A local administrator can change the translation files, use the information to disrupt normal use of the application and weaken the integrity of normal use.