10
CVE-2023-31241
- EPSS 0.01%
- Veröffentlicht 22.05.2023 20:15:10
- Zuletzt bearbeitet 09.12.2024 18:15:21
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Snapone ≫ Orvc SwPlatformpro Version < 7.3.0
Control4 ≫ Ca-1 Version-
Control4 ≫ Ca-10 Version-
Control4 ≫ Ea-1 Version-
Control4 ≫ Ea-3 Version-
Control4 ≫ Ea-5 Version-
Snapone ≫ An-110-rt-2l1w Version-
Snapone ≫ An-110-rt-2l1w-wifi Version-
Snapone ≫ An-310-rt-4l2w Version-
Snapone ≫ Ovrc-300-pro Version-
Snapone ≫ Pakedge Rk-1 Version-
Snapone ≫ Pakedge Rt-3100 Version-
Snapone ≫ Pakedge Wr-1 Version-
Control4 ≫ Ca-10 Version-
Control4 ≫ Ea-1 Version-
Control4 ≫ Ea-3 Version-
Control4 ≫ Ea-5 Version-
Snapone ≫ An-110-rt-2l1w Version-
Snapone ≫ An-110-rt-2l1w-wifi Version-
Snapone ≫ An-310-rt-4l2w Version-
Snapone ≫ Ovrc-300-pro Version-
Snapone ≫ Pakedge Rk-1 Version-
Snapone ≫ Pakedge Rt-3100 Version-
Snapone ≫ Pakedge Wr-1 Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.016 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 10 | 3.9 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
|
| ics-cert@hq.dhs.gov | 8.6 | 3.9 | 4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
|
CWE-420 Unprotected Alternate Channel
The product protects a primary channel, but it does not use the same level of protection for an alternate channel.