CVE-2023-31245
22.05.2023, 20:15
Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP connection. Attackers could impersonate a device and supply malicious information about the devices web server interface. By supplying malicious parameters, an attacker could redirect the user to arbitrary and dangerous locations on the web.
Vendor | Product | Version |
---|---|---|
snapone | orvc | 𝑥 < 7.3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References