Broken authentication on Logitech Options due to misvalidation of Oauth state parameter
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.4epss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Affected products
Logitech · Options