control4 records
4 published records for vendor control4.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-204 Observable Response Discrepancy1
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-420 Unprotected Alternate Channel1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2023-31241No exploit | Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.snapone · orvc · CWE-420 | Critical10.0 | — | 0.8% | May 22, 2023 |
39Monitor | CVE-2023-28386No exploit | Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly.snapone · orvc · CWE-354 | Critical9.8 | — | 0.4% | May 22, 2023 |
24Monitor | CVE-2023-31245No exploit | Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP snapone · orvc · CWE-601 | Medium6.1 | — | 0.4% | May 22, 2023 |
21Monitor | CVE-2023-28412No exploit | When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device.snapone · orvc · CWE-204 | Medium5.3 | — | 0.5% | May 22, 2023 |
- CVE-2023-3124140Plan
Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.
CriticalCVSS 10.0No exploitEPSS 1%snapone · orvcMay 22, 2023
- CVE-2023-2838639Monitor
Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly.
CriticalCVSS 9.8No exploitEPSS 0%snapone · orvcMay 22, 2023
- CVE-2023-3124524Monitor
Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP
MediumCVSS 6.1No exploitEPSS 0%snapone · orvcMay 22, 2023
- CVE-2023-2841221Monitor
When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device.
MediumCVSS 5.3No exploitEPSS 0%snapone · orvcMay 22, 2023