When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack and the OvrC cloud will disclose their information.












Fixes

Solution

Snap One has released the following updates/fixes for the affected products: * OvrC Pro v7.2 has been automatically pushed out to devices to update via OvrC cloud. * OvrC Pro v7.3 has been automatically pushed out to devices to update via OvrC cloud. * Disable UPnP. For more information, see Snap One’s Release Notes https://www.control4.com/docs/product/ovrc-software/release-notes/english/latest/ovrc-software-release-notes-rev-p.pdf .


Workaround

No workaround given by the vendor.

History

Thu, 16 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T21:33:55.805Z

Reserved: 2023-04-26T19:18:23.279Z

Link: CVE-2023-28412

cve-icon Vulnrichment

Updated: 2024-08-02T12:38:25.285Z

cve-icon NVD

Status : Modified

Published: 2023-05-22T20:15:10.330

Modified: 2024-11-21T07:55:00.973

Link: CVE-2023-28412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.