CVE-2024-50381: Missing Authentication for Critical Function in Snap One OVRC cloud
A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and send requests to claim and unclaim devices. The attacker only needs to provide the MAC address of the targeted device and can make a request to unclaim it from its original connection and make a request to claim it.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50381?
CVE-2024-50381 has been classified as a critical vulnerability due to its potential for unauthorized device claims.
How does CVE-2024-50381 allow an attacker to exploit the system?
CVE-2024-50381 allows an attacker to impersonate a Hub device by providing the MAC address of a targeted device.
Which software is affected by CVE-2024-50381?
CVE-2024-50381 affects the Snap One OVRC cloud platform.
How can I mitigate the risk associated with CVE-2024-50381?
To mitigate CVE-2024-50381, ensure that your environment restricts access and uses strong authentication measures.
Is there a patch available for CVE-2024-50381?
As of now, check with Snap One for any security patches or updates addressing CVE-2024-50381.