snapone kayıtları
snapone üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-1391 Use of Weak Credentials1
- CWE-204 Observable Response Discrepancy1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-306 Missing Authentication for Critical Function1
- CWE-310 Cryptographic Issues1
- CWE-319 Cleartext Transmission of Sensitive Information1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2023-31241İstismar yok | Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.snapone · orvc · CWE-420 | Kritik10,0 | — | %0,8 | 22 May 2023 |
39İzleyin | CVE-2023-31240İstismar yok | Snap One OvrC Pro versions prior to 7.2 have their own locally running web server accessible both from the local network and remotely.snapone · orvc · CWE-1391 | Kritik9,8 | — | %0,5 | 22 May 2023 |
39İzleyin | CVE-2023-28386İstismar yok | Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly.snapone · orvc · CWE-354 | Kritik9,8 | — | %0,4 | 22 May 2023 |
35İzleyin | CVE-2024-50381İstismar yok | Missing Authentication for Critical Function in Snap One OVRC cloudsnap one · ovrc cloud · CWE-306 | Yüksek8,8 | — | %0,5 | 2 Ara 2024 |
34İzleyin | CVE-2024-50380İstismar yok | Authentication Bypass by Spoofing in Snap One OVRC cloudsnap one · ovrc cloud · CWE-290 | Yüksek8,7 | — | %0,5 | 2 Ara 2024 |
30İzleyin | CVE-2023-28649İstismar yok | The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it.snapone · orvc · CWE-413 | Yüksek7,5 | — | %0,5 | 22 May 2023 |
30İzleyin | CVE-2023-31193İstismar yok | Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers.snapone · orvc · CWE-319 | Yüksek7,5 | — | %0,4 | 22 May 2023 |
28İzleyin | CVE-2023-25183İstismar yok | In Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a new functionality appsnapone · orvc · CWE-912 | Yüksek7,2 | — | %0,6 | 22 May 2023 |
24İzleyin | CVE-2023-31245İstismar yok | Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP snapone · orvc · CWE-601 | Orta6,1 | — | %0,4 | 22 May 2023 |
21İzleyin | CVE-2023-28412İstismar yok | When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device.snapone · orvc · CWE-204 | Orta5,3 | — | %0,5 | 22 May 2023 |
21İzleyin | CVE-2014-5615İstismar yok | The Snap Secure (aka com.exclaim.snapsecure.app) application 9.5 for Android does not verify X.509 certificates from SSL servers, which allosnapone · snap secure · CWE-310 | Orta5,4 | — | %0,3 | 8 Eyl 2014 |
- CVE-2023-3124140Planlayın
Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.
KritikCVSS 10,0İstismar yokEPSS %1snapone · orvc22 May 2023
- CVE-2023-3124039İzleyin
Snap One OvrC Pro versions prior to 7.2 have their own locally running web server accessible both from the local network and remotely.
KritikCVSS 9,8İstismar yokEPSS %1snapone · orvc22 May 2023
- CVE-2023-2838639İzleyin
Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly.
KritikCVSS 9,8İstismar yokEPSS %0snapone · orvc22 May 2023
- CVE-2024-5038135İzleyin
Missing Authentication for Critical Function in Snap One OVRC cloud
YüksekCVSS 8,8İstismar yokEPSS %1snap one · ovrc cloud2 Ara 2024
- CVE-2024-5038034İzleyin
Authentication Bypass by Spoofing in Snap One OVRC cloud
YüksekCVSS 8,7İstismar yokEPSS %1snap one · ovrc cloud2 Ara 2024
- CVE-2023-2864930İzleyin
The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it.
YüksekCVSS 7,5İstismar yokEPSS %1snapone · orvc22 May 2023
- CVE-2023-3119330İzleyin
Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers.
YüksekCVSS 7,5İstismar yokEPSS %0snapone · orvc22 May 2023
- CVE-2023-2518328İzleyin
In Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a new functionality app
YüksekCVSS 7,2İstismar yokEPSS %1snapone · orvc22 May 2023
- CVE-2023-3124524İzleyin
Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP
OrtaCVSS 6,1İstismar yokEPSS %0snapone · orvc22 May 2023
- CVE-2023-2841221İzleyin
When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device.
OrtaCVSS 5,3İstismar yokEPSS %0snapone · orvc22 May 2023
- CVE-2014-561521İzleyin
The Snap Secure (aka com.exclaim.snapsecure.app) application 9.5 for Android does not verify X.509 certificates from SSL servers, which allo
OrtaCVSS 5,4İstismar yokEPSS %0snapone · snap secure8 Eyl 2014