Lucene search

K
nvd[email protected]NVD:CVE-2023-31245
HistoryMay 22, 2023 - 8:15 p.m.

CVE-2023-31245

2023-05-2220:15:10
CWE-601
web.nvd.nist.gov
3
devices
snap one ovrc cloud
vulnerability
web management interface
impersonation
redirection

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

7

Confidence

High

EPSS

0.001

Percentile

43.7%

Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP connection. Attackers could impersonate a device and supply malicious information about the device’s web server interface. By supplying malicious parameters, an attacker could redirect the user to arbitrary and dangerous locations on the web.

Affected configurations

Nvd
Node
snaponeorvcRange<7.3.0pro
AND
control4ca-1Match-
OR
control4ca-10Match-
OR
control4ea-1Match-
OR
control4ea-3Match-
OR
control4ea-5Match-
OR
snaponean-110-rt-2l1wMatch-
OR
snaponean-110-rt-2l1w-wifiMatch-
OR
snaponean-310-rt-4l2wMatch-
OR
snaponeovrc-300-proMatch-
OR
snaponepakedge_rk-1Match-
OR
snaponepakedge_rt-3100Match-
OR
snaponepakedge_wr-1Match-
VendorProductVersionCPE
snaponeorvc*cpe:2.3:a:snapone:orvc:*:*:*:*:*:pro:*:*
control4ca-1-cpe:2.3:h:control4:ca-1:-:*:*:*:*:*:*:*
control4ca-10-cpe:2.3:h:control4:ca-10:-:*:*:*:*:*:*:*
control4ea-1-cpe:2.3:h:control4:ea-1:-:*:*:*:*:*:*:*
control4ea-3-cpe:2.3:h:control4:ea-3:-:*:*:*:*:*:*:*
control4ea-5-cpe:2.3:h:control4:ea-5:-:*:*:*:*:*:*:*
snaponean-110-rt-2l1w-cpe:2.3:h:snapone:an-110-rt-2l1w:-:*:*:*:*:*:*:*
snaponean-110-rt-2l1w-wifi-cpe:2.3:h:snapone:an-110-rt-2l1w-wifi:-:*:*:*:*:*:*:*
snaponean-310-rt-4l2w-cpe:2.3:h:snapone:an-310-rt-4l2w:-:*:*:*:*:*:*:*
snaponeovrc-300-pro-cpe:2.3:h:snapone:ovrc-300-pro:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 131

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

7

Confidence

High

EPSS

0.001

Percentile

43.7%

Related for NVD:CVE-2023-31245