CVE-2023-22315: High severity snap one wattbox wb-300-ip-3 vulnerability
Published Jan 30, 2023
·Updated
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior use a proprietary local area network (LAN) protocol that does not verify updates to the device. An attacker could upload a malformed update file to the device and execute arbitrary code.
Affected Software
3 affected components
Snap One Wattbox WB-300-IP-3: versions WB10.9a17 and prior
Snapav Wattbox Wb-300-ip-3 Firmware<=wb10.9a17
Snapav Wattbox Wb-300-ip-3
Remediation
Information
Snap One has released the following updates for the affected products:
* Version WB10.B929 https://app.ovrc.com/#/user-settings (login required)
Event History
Jan 30, 2023
CVE Published
via MITRE·09:58 PM
Data Sourced
via MITRE·09:58 PM
RemedyDescriptionSeverityWeakness
Aug 2, 2024
Data Sourced
via ICS·10:10 AM
SeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-22315?
CVE-2023-22315 has a critical severity level due to the potential for arbitrary code execution.
2
How can I fix CVE-2023-22315?
To mitigate CVE-2023-22315, upgrade to the latest firmware version provided by Snap One.
3
What does CVE-2023-22315 exploit?
CVE-2023-22315 exploits a weakness in the update verification process of Snap One Wattbox WB-300-IP-3 devices.
4
Who is affected by CVE-2023-22315?
CVE-2023-22315 affects Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and earlier.
5
What can an attacker do with CVE-2023-22315?
An attacker can upload a malformed update file to the affected device to execute arbitrary code.