CVE-2023-31241: Critical severity snap one ovrc vulnerability
Published May 22, 2023
·Updated
Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.
Affected Software
27 affected componentsFixes available
Snap One OvrC Pro<7.3
7.3
All of the following
Snapone Orvc Pro<7.3.0
Any of the following
Control4 Ca-1
Control4 Ca-10
Control4 Ea-1
Control4 Ea-3
Control4 Ea-5
Snapone An-110-rt-2l1w
Snapone An-110-rt-2l1w-wifi
Snapone An-310-rt-4l2w
Snapone Ovrc-300-pro
Snapone Pakedge Rk-1
Snapone Pakedge Rt-3100
Snapone Pakedge Wr-1
Snapone Orvc Pro<7.3.0
Control4 Ca-1
Control4 Ca-10
Control4 Ea-1
Control4 Ea-3
Control4 Ea-5
Snapone An-110-rt-2l1w
Snapone An-110-rt-2l1w-wifi
Snapone An-310-rt-4l2w
Snapone Ovrc-300-pro
Snapone Pakedge Rk-1
Snapone Pakedge Rt-3100
Snapone Pakedge Wr-1
Remediation
Information
Snap One has released the following updates/fixes for the affected products:
* OvrC Pro v7.2 has been automatically pushed out to devices to update via OvrC cloud.
* OvrC Pro v7.3 has been automatically pushed out to devices to update via OvrC cloud.
* Disable UPnP.
For more information, see Snap One’s Release Notes https://www.control4.com/docs/product/ovrc-software/release-notes/english/latest/ovrc-software-release-notes-rev-p.pdf .
Event History
May 22, 2023
CVE Published
via MITRE·07:26 PM
Data Sourced
via MITRE·07:26 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-31241?
CVE-2023-31241 is classified as a high severity vulnerability due to its potential for device claiming by attackers.
2
How do I fix CVE-2023-31241?
To remediate CVE-2023-31241, update Snap One OvrC Pro to a version higher than 7.3.
3
Who is affected by CVE-2023-31241?
CVE-2023-31241 affects Snap One OvrC Pro versions up to and including 7.3.
4
What type of attack is possible with CVE-2023-31241?
CVE-2023-31241 allows attackers to bypass authentication requirements and claim devices.
5
Is there a vulnerable product listed under CVE-2023-31241?
Yes, the vulnerable product is Snap One OvrC Pro, specifically versions up to 7.3.