PatchSiren cyber security CVE debrief
CVE-2024-54681 Ossur CVE debrief
Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an attacker that has already full access to the mobile platform to compromise the translations for the application.
- Vendor
- Ossur
- Product
- Logic Mobile Application
- CVSS
- LOW 3.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-12-19
- Original CVE updated
- 2024-12-19
- Advisory published
- 2024-12-19
- Advisory updated
- 2024-12-19
Who should care
Organizations and individuals using the Ossur Logic Mobile Application for medical device management should apply the update to version 1.5.5 or later. Security teams supporting healthcare environments with mobile medical applications should verify patch deployment across managed device fleets.
Technical summary
The Ossur Logic Mobile Application contained multiple bash files in its private application directory. These files could be exploited by an attacker who has already achieved full access to the mobile platform to compromise the application's translations. The vulnerability requires local access with elevated privileges and does not enable remote exploitation. The primary impact is limited to integrity of application translations, with no confidentiality or availability impact beyond the translation subsystem.
Defensive priority
LOW
Recommended defensive actions
- Update the Ossur Logic Mobile Application to version 1.5.5 or later through the official app store on your mobile device.
- No additional user action is required after updating to the patched version.
- Ensure mobile devices running the application maintain appropriate platform-level access controls to prevent unauthorized local access.
Evidence notes
CISA published ICSMA-24-354-01 on 2024-12-19, identifying this vulnerability in the Ossur Logic Mobile Application. The advisory notes that bash files present in the application's private directory could be leveraged by an attacker with full access to the mobile platform to compromise application translations. The CVSS 3.1 score of 3.5 (LOW) reflects the requirement for prior full platform access and limited impact scope.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-54681 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-54681
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-54681 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-54681
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsma-24-354-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-354-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.