CVE-2024-54681 Details
Description
Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an attacker that has already full access to the mobile platform to compromise the translations for the application.
A command injection vulnerability has been identified in the Ossur Mobile Logic Application, specifically in versions prior to 1.5.5. The issue arises from multiple bash files being present in the application's private directory. An attacker with full access to the mobile platform could exploit this vulnerability to manipulate the application's translation files, disrupting normal functionality.
Users are advised to download version 1.5.5 or later of the Ossur Mobile Logic Application. The latest version can be obtained through the app store on respective mobile devices.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 17, 2025CISA-ADP
Assessed Jan 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-354-01 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Ossur Mobile Logic Application | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 17, 2025 | New CVE Received | [email protected] |
Volerion