CVE-2023-31240: Critical severity snap one ovrc vulnerability
Published May 22, 2023
·Updated
Snap One OvrC Pro versions prior to 7.2 have their own locally running web server accessible both from the local network and remotely. OvrC cloud contains a hidden superuser account accessible through hard-coded credentials.
Affected Software
2 affected componentsFixes available
Snap One OvrC Pro<7.3
7.3
Snapone Orvc Pro<7.2.0
Remediation
Information
Snap One has released the following updates/fixes for the affected products:
* OvrC Pro v7.2 has been automatically pushed out to devices to update via OvrC cloud.
* OvrC Pro v7.3 has been automatically pushed out to devices to update via OvrC cloud.
* Disable UPnP.
For more information, see Snap One’s Release Notes https://www.control4.com/docs/product/ovrc-software/release-notes/english/latest/ovrc-software-release-notes-rev-p.pdf .
Event History
May 22, 2023
CVE Published
via MITRE·07:58 PM
Data Sourced
via MITRE·07:58 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-31240?
CVE-2023-31240 is categorized as a critical vulnerability due to the presence of hard-coded superuser credentials.
2
How do I fix CVE-2023-31240?
To fix CVE-2023-31240, update Snap One OvrC Pro to version 7.3 or later.
3
What systems are affected by CVE-2023-31240?
CVE-2023-31240 affects Snap One OvrC Pro versions prior to 7.2.
4
What risks are associated with CVE-2023-31240?
CVE-2023-31240 poses risks such as unauthorized remote access to the OvrC cloud and potential exploitation of the hidden superuser account.
5
Is patching necessary for CVE-2023-31240?
Yes, patching is necessary for CVE-2023-31240 to mitigate the risks associated with the vulnerability.