Description

























Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP connection. Attackers could impersonate a device and supply malicious information about the device’s web server interface. By supplying malicious parameters, an attacker could redirect the user to arbitrary and dangerous locations on the web.













Published: 2023-05-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Snap One has released the following updates/fixes for the affected products: * OvrC Pro v7.2 has been automatically pushed out to devices to update via OvrC cloud. * OvrC Pro v7.3 has been automatically pushed out to devices to update via OvrC cloud. * Disable UPnP. For more information, see Snap One’s Release Notes https://www.control4.com/docs/product/ovrc-software/release-notes/english/latest/ovrc-software-release-notes-rev-p.pdf .

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-35560 Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP connection. Attackers could impersonate a device and supply malicious information about the device’s web server interface. By supplying malicious parameters, an attacker could redirect the user to arbitrary and dangerous locations on the web.
History

Thu, 16 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Control4 Ca-1 Ca-10 Ea-1 Ea-3 Ea-5
Snapone An-110-rt-2l1w An-110-rt-2l1w-wifi An-310-rt-4l2w Orvc Ovrc-300-pro Pakedge Rk-1 Pakedge Rt-3100 Pakedge Wr-1
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T21:33:28.000Z

Reserved: 2023-04-26T19:18:23.299Z

Link: CVE-2023-31245

cve-icon Vulnrichment

Updated: 2024-08-02T14:53:30.667Z

cve-icon NVD

Status : Modified

Published: 2023-05-22T20:15:10.807

Modified: 2024-11-21T08:01:41.973

Link: CVE-2023-31245

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses