CVE-2023-31245
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP connection. Attackers could impersonate a device and supply malicious information about the device’s web server interface. By supplying malicious parameters, an attacker could redirect the user to arbitrary and dangerous locations on the web.
Affected (1)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.3.0 |
| Running on/with | Platform Versions |
|---|---|
Control4 Ca 1 | All versions |
Control4 Ca 10 | All versions |
Control4 Ea 1 | All versions |
Control4 Ea 3 | All versions |
Control4 Ea 5 | All versions |
Snapone An 110 Rt 2l1w | All versions |
Snapone An 110 Rt 2l1w Wifi | All versions |
Snapone An 310 Rt 4l2w | All versions |
Snapone Ovrc 300 Pro | All versions |
Snapone Pakedge Rk 1 | All versions |
Snapone Pakedge Rt 3100 | All versions |
Snapone Pakedge Wr 1 | All versions |
References (4)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: ics-cert@hq.dhs.gov
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Timeline
No history available yet.