Exposure of Sensitive System Information to an Unauthorized Control Sphere in Össur Logic - CVE-2024-53683

 

Exposure of Sensitive System Information to an Unauthorized Control Sphere in Össur Logic - CVE-2024-53683

Published: January 8, 2025


Vulnerability identifier: #VU102457
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-53683
CWE-ID: CWE-497
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to the valid set of credentials in a .js file and a static token for communication are obtained from the decompiled IPA. A local administrator can change the translation files, use the information to disrupt normal use of the application and weaken the integrity of normal use.


Affected software

Össur Logic

How to mitigate CVE-2024-53683

Install updates from vendor's website.

Össur Logic - update to 1.5.5

External References

Related Security Bulletins