7.1

CVE-2023-31245

























Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP connection. Attackers could impersonate a device and supply malicious information about the device’s web server interface. By supplying malicious parameters, an attacker could redirect the user to arbitrary and dangerous locations on the web.













Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SnaponeOrvc SwPlatformpro Version < 7.3.0
   Control4Ca-1 Version-
   Control4Ca-10 Version-
   Control4Ea-1 Version-
   Control4Ea-3 Version-
   Control4Ea-5 Version-
   SnaponeAn-110-rt-2l1w Version-
   SnaponeAn-110-rt-2l1w-wifi Version-
   SnaponeAn-310-rt-4l2w Version-
   SnaponeOvrc-300-pro Version-
   SnaponePakedge Rk-1 Version-
   SnaponePakedge Rt-3100 Version-
   SnaponePakedge Wr-1 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.07% 0.221
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
ics-cert@hq.dhs.gov 7.1 2.8 3.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.