CVE-2022-0916: Broken authentication on Logitech Options due to misvalidation of Oauth state parameter
Published May 3, 2022
·Updated
An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations.
Affected Software
1 affected component
Logitech Options<9.60.87
Remediation
Information
Update to Logitech Options 9.60.87
Event History
May 3, 2022
CVE Published
via MITRE·01:40 PM
Data Sourced
via MITRE·01:40 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-0916?
CVE-2022-0916 has a medium severity rating due to its potential exposure to CSRF attacks during OAuth 2.0 authentication.
2
How do I fix CVE-2022-0916?
To fix CVE-2022-0916, update Logitech Options to version 9.60.87 or later.
3
What types of attacks does CVE-2022-0916 expose applications to?
CVE-2022-0916 exposes applications to Cross-Site Request Forgery (CSRF) attacks.
4
Which versions of Logitech Options are affected by CVE-2022-0916?
Versions of Logitech Options prior to 9.60.87 are affected by CVE-2022-0916.
5
Is user data at risk due to CVE-2022-0916?
Yes, user data can be at risk due to unauthorized actions triggered by CSRF attacks associated with CVE-2022-0916.