2024-08-28 09:00:34 +00:00
{
2024-09-10 09:00:34 +00:00
"data_version" : "4.0" ,
2024-08-28 09:00:34 +00:00
"data_type" : "CVE" ,
"data_format" : "MITRE" ,
"CVE_data_meta" : {
"ID" : "CVE-2024-8258" ,
2024-09-10 09:00:34 +00:00
"ASSIGNER" : "cve-coordination@logitech.com" ,
"STATE" : "PUBLIC"
2024-08-28 09:00:34 +00:00
} ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2024-09-10 09:00:34 +00:00
"value" : "Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code via insecure Electron Fuses configuration."
2024-08-28 09:00:34 +00:00
}
]
2024-09-10 09:00:34 +00:00
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "CWE-94 Improper Control of Generation of Code ('Code Injection')" ,
"cweId" : "CWE-94"
}
]
}
]
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"vendor_name" : "Logitech" ,
"product" : {
"product_data" : [
{
"product_name" : "Logitech Options Plus" ,
"version" : {
"version_data" : [
{
"version_value" : "not down converted" ,
"x_cve_json_5_version_data" : {
"versions" : [
{
"lessThan" : "1.70" ,
"status" : "affected" ,
"version" : "1.60.496306" ,
"versionType" : "semver"
} ,
{
"status" : "unaffected" ,
"version" : "1.70"
}
] ,
"defaultStatus" : "unaffected"
}
}
]
}
}
]
}
}
]
}
} ,
"references" : {
"reference_data" : [
{
"url" : "https://www.electronjs.org/docs/latest/tutorial/fuses" ,
"refsource" : "MISC" ,
"name" : "https://www.electronjs.org/docs/latest/tutorial/fuses"
} ,
{
"url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-50643" ,
"refsource" : "MISC" ,
"name" : "https://nvd.nist.gov/vuln/detail/CVE-2023-50643"
} ,
{
"url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-49314" ,
"refsource" : "MISC" ,
"name" : "https://nvd.nist.gov/vuln/detail/CVE-2023-49314"
} ,
{
"url" : "https://github.com/r3ggi/electroniz3r" ,
"refsource" : "MISC" ,
"name" : "https://github.com/r3ggi/electroniz3r"
}
]
} ,
"generator" : {
"engine" : "Vulnogram 0.2.0"
} ,
"source" : {
"discovery" : "EXTERNAL"
} ,
"solution" : [
{
"lang" : "en" ,
"supportingMedia" : [
{
"base64" : false ,
"type" : "text/html" ,
"value" : "<p>Update to Logitech Options Plus version 1.70 or later.</p><br>"
}
] ,
"value" : "Update to Logitech Options Plus version 1.70 or later."
}
] ,
"credits" : [
{
"lang" : "en" ,
"value" : "Dave F - https://hackerone.com/dave23p"
}
]
2024-08-28 09:00:34 +00:00
}