CVE-2023-28412
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack and the OvrC cloud will disclose their information.
Affected (1)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.3.0 |
| Running on/with | Platform Versions |
|---|---|
Control4 Ca 1 | All versions |
Control4 Ca 10 | All versions |
Control4 Ea 1 | All versions |
Control4 Ea 3 | All versions |
Control4 Ea 5 | All versions |
Snapone An 110 Rt 2l1w | All versions |
Snapone An 110 Rt 2l1w Wifi | All versions |
Snapone An 310 Rt 4l2w | All versions |
Snapone Ovrc 300 Pro | All versions |
Snapone Pakedge Rk 1 | All versions |
Snapone Pakedge Rt 3100 | All versions |
Snapone Pakedge Wr 1 | All versions |
Related CWEs
CWE-203
Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
CWE-204
Observable Response Discrepancy
The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
References (4)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: ics-cert@hq.dhs.gov
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Timeline
No history available yet.