« Volver al listado

CVE-2023-31245

Estado: ModificadaMedia (6.1)—

Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP connection. Attackers could impersonate a device and supply malicious information about the device’s web server interface. By supplying malicious parameters, an attacker could redirect the user to arbitrary and dangerous locations on the web.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-31245",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-31245",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-01-16T20:21:09.583592Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "ics-cert@hq.dhs.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.7,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "Snap One",
          "product": "OvrC Cloud",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "7.3",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-05-22T20:15:10.807",
  "references": [
    {
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-136-01",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://www.control4.com/docs/product/ovrc-software/release-notes/english/latest/ovrc-software-release-notes-rev-p.pdf",
      "tags": [
        "Release Notes"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-136-01",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.control4.com/docs/product/ovrc-software/release-notes/english/latest/ovrc-software-release-notes-rev-p.pdf",
      "tags": [
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ics-cert@hq.dhs.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-601"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\nDevices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP connection. Attackers could impersonate a device and supply malicious information about the device’s web server interface. By supplying malicious parameters, an attacker could redirect the user to arbitrary and dangerous locations on the web.\n\n\n\n\n\n\n\n\n\n\n\n\n\n"
    }
  ],
  "lastModified": "2026-06-17T05:56:40.277",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:snapone:orvc:*:*:*:*:*:pro:*:*",
              "vulnerable": true,
              "matchCriteriaId": "415E3C3D-6B2F-4095-B7F1-E3F777E01172",
              "versionEndExcluding": "7.3.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:control4:ca-1:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "910274AB-35AF-428C-84D7-36774DEB59D8"
            },
            {
              "criteria": "cpe:2.3:h:control4:ca-10:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "852189C9-7720-468D-BCE0-28DFC051AEDC"
            },
            {
              "criteria": "cpe:2.3:h:control4:ea-1:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C61FA2AE-A962-4D60-BBCF-751FDB5215B9"
            },
            {
              "criteria": "cpe:2.3:h:control4:ea-3:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B6310809-0890-4113-837C-0074706B4E6B"
            },
            {
              "criteria": "cpe:2.3:h:control4:ea-5:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F7ADAAF7-9B0B-4002-8158-FC6B0EAB6055"
            },
            {
              "criteria": "cpe:2.3:h:snapone:an-110-rt-2l1w:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B5B50505-B496-4172-813E-CA174EE2D4DF"
            },
            {
              "criteria": "cpe:2.3:h:snapone:an-110-rt-2l1w-wifi:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "04744281-B935-4272-8582-85C6162881F8"
            },
            {
              "criteria": "cpe:2.3:h:snapone:an-310-rt-4l2w:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CCD83E46-F84F-49F8-9601-ABC03292E0F6"
            },
            {
              "criteria": "cpe:2.3:h:snapone:ovrc-300-pro:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F5B44DFB-CC8D-4342-907B-D34F9EAB5CEB"
            },
            {
              "criteria": "cpe:2.3:h:snapone:pakedge_rk-1:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B2982D38-80BF-4041-9F59-D26C152D24D9"
            },
            {
              "criteria": "cpe:2.3:h:snapone:pakedge_rt-3100:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "061055F0-D742-4227-ADC2-1793979F9463"
            },
            {
              "criteria": "cpe:2.3:h:snapone:pakedge_wr-1:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CF7BD251-BB2F-4C49-8B1E-8EB26580DFDB"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}