Lucene search

K
cveIcscertCVE-2023-28412
HistoryMay 22, 2023 - 8:15 p.m.

CVE-2023-28412

2023-05-2220:15:10
CWE-204
CWE-203
icscert
web.nvd.nist.gov
28
cve-2023-28412
snap one
ovrc
cloud servers
mac address
enumeration
information disclosure

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

43.7%

When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack and the OvrC cloud will disclose their information.

Affected configurations

Nvd
Node
snaponeorvcRange<7.3.0pro
AND
control4ca-1Match-
OR
control4ca-10Match-
OR
control4ea-1Match-
OR
control4ea-3Match-
OR
control4ea-5Match-
OR
snaponean-110-rt-2l1wMatch-
OR
snaponean-110-rt-2l1w-wifiMatch-
OR
snaponean-310-rt-4l2wMatch-
OR
snaponeovrc-300-proMatch-
OR
snaponepakedge_rk-1Match-
OR
snaponepakedge_rt-3100Match-
OR
snaponepakedge_wr-1Match-
VendorProductVersionCPE
snaponeorvc*cpe:2.3:a:snapone:orvc:*:*:*:*:*:pro:*:*
control4ca-1-cpe:2.3:h:control4:ca-1:-:*:*:*:*:*:*:*
control4ca-10-cpe:2.3:h:control4:ca-10:-:*:*:*:*:*:*:*
control4ea-1-cpe:2.3:h:control4:ea-1:-:*:*:*:*:*:*:*
control4ea-3-cpe:2.3:h:control4:ea-3:-:*:*:*:*:*:*:*
control4ea-5-cpe:2.3:h:control4:ea-5:-:*:*:*:*:*:*:*
snaponean-110-rt-2l1w-cpe:2.3:h:snapone:an-110-rt-2l1w:-:*:*:*:*:*:*:*
snaponean-110-rt-2l1w-wifi-cpe:2.3:h:snapone:an-110-rt-2l1w-wifi:-:*:*:*:*:*:*:*
snaponean-310-rt-4l2w-cpe:2.3:h:snapone:an-310-rt-4l2w:-:*:*:*:*:*:*:*
snaponeovrc-300-pro-cpe:2.3:h:snapone:ovrc-300-pro:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 131

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "OvrC Cloud",
    "vendor": "Snap One",
    "versions": [
      {
        "lessThan": "7.3",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

43.7%

Related for CVE-2023-28412