CVE-2023-24020: Critical severity snap one wattbox wb-300-ip-3 vulnerability
Published Jan 30, 2023
·Updated
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior could bypass the brute force protection, allowing multiple attempts to force a login.
Affected Software
3 affected components
Snap One Wattbox WB-300-IP-3: versions WB10.9a17 and prior
Snapav Wattbox Wb-300-ip-3 Firmware<=wb10.9a17
Snapav Wattbox Wb-300-ip-3
Remediation
Information
Snap One has released the following updates for the affected products:
* Version WB10.B929 https://app.ovrc.com/#/user-settings (login required)
Event History
Jan 30, 2023
CVE Published
via MITRE·09:54 PM
Data Sourced
via MITRE·09:54 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-24020.
2
What is the severity of CVE-2023-24020?
The severity of CVE-2023-24020 is critical with a CVSS score of 9.8.
3
What is the affected software for CVE-2023-24020?
The affected software for CVE-2023-24020 is Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior.
4
What is the impact of CVE-2023-24020?
CVE-2023-24020 allows multiple attempts to force a login by bypassing the brute force protection.
5
Are there any references available for CVE-2023-24020?
Yes, you can find more information about CVE-2023-24020 at the following link: https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-03