CVE-2023-31193: High severity snap one ovrc vulnerability
Published May 22, 2023
·Updated
Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers. Because they do not use HTTPS, OvrC Pro devices are susceptible to exploitation.
Affected Software
2 affected componentsFixes available
Snap One OvrC Pro<7.3
7.3
Snapone Orvc Pro<7.3.0
Remediation
Information
Snap One has released the following updates/fixes for the affected products:
* OvrC Pro v7.2 has been automatically pushed out to devices to update via OvrC cloud.
* OvrC Pro v7.3 has been automatically pushed out to devices to update via OvrC cloud.
* Disable UPnP.
For more information, see Snap One’s Release Notes https://www.control4.com/docs/product/ovrc-software/release-notes/english/latest/ovrc-software-release-notes-rev-p.pdf .
Event History
May 22, 2023
CVE Published
via MITRE·07:28 PM
Data Sourced
via MITRE·07:28 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-31193?
CVE-2023-31193 is considered a high-severity vulnerability due to the potential exploitation via unencrypted HTTP connections.
2
How do I fix CVE-2023-31193?
To fix CVE-2023-31193, upgrade your Snap One OvrC Pro software to version 7.3 or later.
3
What type of exploit is associated with CVE-2023-31193?
CVE-2023-31193 allows attackers to exploit unencrypted HTTP connections, potentially leading to unauthorized access.
4
Which versions of Snap One OvrC Pro are affected by CVE-2023-31193?
CVE-2023-31193 affects all versions of Snap One OvrC Pro prior to 7.3.
5
Is there a workaround for CVE-2023-31193?
There is no official workaround for CVE-2023-31193; upgrading to the latest version is recommended.