logmein 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。
公開された問題は vendor risk memory corruption and vendor risk denial of service に関連することが多く、vendor surface software deployment and vendor surface production workloads の文脈で アプリケーションクラッシュ and vendor impact memory corruption などの暴露リスクを伴う場合があります。
掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2020-35208 | An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. The password authentication for unlocking can be bypassed by forcing the authentication result to be true through runtime manipulation. In other words, an attacker could authenticate with an arbitrary password. NOTE: the vendor has indicated that this is not an attack of interest within the context of their threat model, which excludes jailbroken devices | [email protected] | 5.7 | 0.47% | 2020-12-12 | 2024-11-21 |
| CVE-2020-35207 | An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. The PIN authentication for unlocking can be bypassed by forcing the authentication result to be true through runtime manipulation. In other words, an attacker could authenticate with an arbitrary PIN. NOTE: the vendor has indicated that this is not an attack of interest within the context of their threat model, which excludes jailbroken devices | [email protected] | 5.7 | 0.47% | 2020-12-12 | 2024-11-21 |
| CVE-2013-5114 | LastPass prior to 2.5.1 allows secure wipe bypass. | [email protected] | 6.1 | 0.58% | 2020-01-31 | 2024-11-21 |
| CVE-2013-5113 | LastPass prior to 2.5.1 has an insecure PIN implementation. | [email protected] | 6.8 | 0.59% | 2020-01-31 | 2024-11-21 |
| CVE-2019-16371 | LogMeIn LastPass before 4.33.0 allows attackers to construct a crafted web site that captures the credentials for a victim's account on a previously visited web site, because do_popupregister can be bypassed via clickjacking. | [email protected] | 8.2 | 1.18% | 2019-09-16 | 2024-11-21 |
| CVE-2018-10193 | LogMeIn LastPass through 4.15.0 allows remote attackers to cause a denial of service (browser hang) via an HTML document because the resource consumption of onloadwff.js grows with the number of INPUT elements. | [email protected] | 7.5 | 4.83% | 2018-04-18 | 2024-11-21 |
| CVE-2008-7053 | LogMeIn Remote Access Utility ActiveX control (RACtrl.dll) allows remote attackers to cause a denial of service (crash) by setting the fgcolor and bgcolor properties to certain long values that trigger memory corruption. | [email protected] | 9.3 | 6.54% | 2009-08-24 | 2026-04-23 |