CVE-2023-25183: High severity snap one ovrc vulnerability
Published May 22, 2023
·Updated
In Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a new functionality appears that could allow users to execute arbitrary commands on the hub device.
Affected Software
3 affected componentsFixes available
Snap One OvrC Pro<7.3
7.3
Snapone Orvc Pro<7.3.0
Snapone Ovrc-300-pro
Remediation
Information
Snap One has released the following updates/fixes for the affected products:
* OvrC Pro v7.2 has been automatically pushed out to devices to update via OvrC cloud.
* OvrC Pro v7.3 has been automatically pushed out to devices to update via OvrC cloud.
* Disable UPnP.
For more information, see Snap One’s Release Notes https://www.control4.com/docs/product/ovrc-software/release-notes/english/latest/ovrc-software-release-notes-rev-p.pdf .
Event History
May 22, 2023
CVE Published
via MITRE·08:04 PM
Data Sourced
via MITRE·08:04 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-25183?
CVE-2023-25183 is classified as a high severity vulnerability due to its potential for arbitrary command execution by superusers.
2
How do I fix CVE-2023-25183?
To fix CVE-2023-25183, upgrade Snap One OvrC Pro to version 7.3 or later.
3
What versions of Snap One OvrC Pro are affected by CVE-2023-25183?
CVE-2023-25183 affects Snap One OvrC Pro versions prior to 7.2.
4
What type of vulnerability is CVE-2023-25183?
CVE-2023-25183 is a command injection vulnerability that could be exploited by users to execute arbitrary commands.
5
Who is the vendor of the vulnerable product CVE-2023-25183?
The vendor of the vulnerable product in CVE-2023-25183 is Snap One.