Vulnerabilities > Logitech

DATE CVE VULNERABILITY TITLE RISK
2018-12-20 CVE-2018-15723 Unspecified vulnerability in Logitech Harmony HUB Firmware
The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request.
network
low complexity
logitech
critical
9.8
2018-12-20 CVE-2018-15722 OS Command Injection vulnerability in Logitech Harmony HUB Firmware
The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request.
network
high complexity
logitech CWE-78
8.1
2018-12-20 CVE-2018-15721 Improper Authentication vulnerability in Logitech Harmony HUB Firmware
The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request.
network
low complexity
logitech CWE-287
critical
9.8
2018-12-20 CVE-2018-15720 Use of Hard-coded Credentials vulnerability in Logitech Harmony HUB Firmware
Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local API.
network
low complexity
logitech CWE-798
critical
9.8
2018-07-26 CVE-2018-0621 Untrusted Search Path vulnerability in Logitech Connection Utility Software 2.00.3/2.20.28/2.30.6
Untrusted search path vulnerability in LOGICOOL CONNECTION UTILITY SOFTWARE versions before 2.30.9 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
logitech CWE-426
7.8
2018-07-26 CVE-2018-0620 Untrusted Search Path vulnerability in Logitech Game Software
Untrusted search path vulnerability in LOGICOOL Game Software versions before 8.87.116 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
logitech CWE-426
7.8
2017-11-10 CVE-2017-16568 Cross-site Scripting vulnerability in Logitech Media Server 7.9.0
Cross-site scripting (XSS) vulnerability in Logitech Media Server 7.9.0 allows remote attackers to inject arbitrary web script or HTML via a radio URL.
network
low complexity
logitech CWE-79
5.4
2017-11-10 CVE-2017-16567 Cross-site Scripting vulnerability in Logitech Media Server 7.9.0
Cross-site scripting (XSS) vulnerability in Logitech Media Server 7.9.0 allows remote attackers to inject arbitrary web script or HTML via a "favorite."
network
low complexity
logitech CWE-79
5.4
2017-10-23 CVE-2017-15687 Cross-site Scripting vulnerability in Logitech Media Server
DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1 via a crafted URI.
network
low complexity
logitech CWE-79
6.1
2016-08-02 CVE-2016-6257 Cryptographic Issues vulnerability in multiple products
The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject encrypted keyboard input into the system by leveraging proximity to the dongle, aka a "KeyJack injection attack."
6.5