CVE-2023-28412: Medium severity snap one ovrc vulnerability
Published May 22, 2023
·Updated
When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack and the OvrC cloud will disclose their information.
Affected Software
14 affected componentsFixes available
Snap One OvrC Pro<7.3
7.3
Snapone Orvc Pro<7.3.0
Control4 Ca-1
Control4 Ca-10
Control4 Ea-1
Control4 Ea-3
Control4 Ea-5
Snapone An-110-rt-2l1w
Snapone An-110-rt-2l1w-wifi
Snapone An-310-rt-4l2w
Snapone Ovrc-300-pro
Snapone Pakedge Rk-1
Snapone Pakedge Rt-3100
Snapone Pakedge Wr-1
Remediation
Information
Snap One has released the following updates/fixes for the affected products:
* OvrC Pro v7.2 has been automatically pushed out to devices to update via OvrC cloud.
* OvrC Pro v7.3 has been automatically pushed out to devices to update via OvrC cloud.
* Disable UPnP.
For more information, see Snap One’s Release Notes https://www.control4.com/docs/product/ovrc-software/release-notes/english/latest/ovrc-software-release-notes-rev-p.pdf .
Event History
May 22, 2023
CVE Published
via MITRE·07:24 PM
Data Sourced
via MITRE·07:24 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-28412?
CVE-2023-28412 is considered a medium severity vulnerability due to potential information disclosure.
2
How do I fix CVE-2023-28412?
To fix CVE-2023-28412, upgrade Snap One OvrC Pro to version 7.3 or later.
3
What type of information is disclosed by CVE-2023-28412?
CVE-2023-28412 allows an attacker to enumerate devices and access their information using random MAC addresses.
4
Which versions of Snap One OvrC Pro are affected by CVE-2023-28412?
All versions of Snap One OvrC Pro prior to 7.3 are affected by CVE-2023-28412.
5
Is there a workaround for CVE-2023-28412?
No specific workaround has been provided for CVE-2023-28412; the recommended action is to upgrade to the fixed version.