CVE-2023-31245: High severity snap one ovrc vulnerability
Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP connection. Attackers could impersonate a device and supply malicious information about the device’s web server interface. By supplying malicious parameters, an attacker could redirect the user to arbitrary and dangerous locations on the web.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-31245?
CVE-2023-31245 is categorized as a moderate severity vulnerability that allows attackers to impersonate devices.
How do I fix CVE-2023-31245?
To resolve CVE-2023-31245, users should upgrade to the latest version of the Snap One OvrC Pro software beyond version 7.3.
What devices are affected by CVE-2023-31245?
CVE-2023-31245 affects devices using Snap One OvrC cloud, specifically those running version 7.3 or lower.
What does CVE-2023-31245 exploit?
CVE-2023-31245 exploits the web interface of the device management system by allowing attackers to supply malicious parameters.
Is CVE-2023-31245 related to other vulnerabilities?
CVE-2023-31245 is specific to the Snap One OvrC service and does not have known direct connections to other vulnerabilities reported in the same product.