CVE-2023-28386
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly. The device only calculates the MD5 hash of the firmware and does not check using a private-public key mechanism. The lack of complete PKI system firmware signature could allow attackers to upload arbitrary firmware updates, resulting in code execution.
Affected (1)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.3.0 |
| Running on/with | Platform Versions |
|---|---|
Control4 Ca 1 | All versions |
Control4 Ca 10 | All versions |
Control4 Ea 1 | All versions |
Control4 Ea 3 | All versions |
Control4 Ea 5 | All versions |
Snapone An 110 Rt 2l1w | All versions |
Snapone An 110 Rt 2l1w Wifi | All versions |
Snapone An 310 Rt 4l2w | All versions |
Snapone Ovrc 300 Pro | All versions |
Snapone Pakedge Rk 1 | All versions |
Snapone Pakedge Rt 3100 | All versions |
Snapone Pakedge Wr 1 | All versions |
Related CWEs
CWE-345
Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CWE-354
Improper Validation of Integrity Check Value
The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.
References (4)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: ics-cert@hq.dhs.gov
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Timeline
No history available yet.