snapone records
11 published records for vendor snapone.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1391 Use of Weak Credentials1
- CWE-204 Observable Response Discrepancy1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-306 Missing Authentication for Critical Function1
- CWE-310 Cryptographic Issues1
- CWE-319 Cleartext Transmission of Sensitive Information1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2023-31241No exploit | Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.snapone · orvc · CWE-420 | Critical10.0 | — | 0.8% | May 22, 2023 |
39Monitor | CVE-2023-31240No exploit | Snap One OvrC Pro versions prior to 7.2 have their own locally running web server accessible both from the local network and remotely.snapone · orvc · CWE-1391 | Critical9.8 | — | 0.5% | May 22, 2023 |
39Monitor | CVE-2023-28386No exploit | Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly.snapone · orvc · CWE-354 | Critical9.8 | — | 0.4% | May 22, 2023 |
35Monitor | CVE-2024-50381No exploit | Missing Authentication for Critical Function in Snap One OVRC cloudsnap one · ovrc cloud · CWE-306 | High8.8 | — | 0.5% | Dec 2, 2024 |
34Monitor | CVE-2024-50380No exploit | Authentication Bypass by Spoofing in Snap One OVRC cloudsnap one · ovrc cloud · CWE-290 | High8.7 | — | 0.5% | Dec 2, 2024 |
30Monitor | CVE-2023-28649No exploit | The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it.snapone · orvc · CWE-413 | High7.5 | — | 0.5% | May 22, 2023 |
30Monitor | CVE-2023-31193No exploit | Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers.snapone · orvc · CWE-319 | High7.5 | — | 0.4% | May 22, 2023 |
28Monitor | CVE-2023-25183No exploit | In Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a new functionality appsnapone · orvc · CWE-912 | High7.2 | — | 0.6% | May 22, 2023 |
24Monitor | CVE-2023-31245No exploit | Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP snapone · orvc · CWE-601 | Medium6.1 | — | 0.4% | May 22, 2023 |
21Monitor | CVE-2023-28412No exploit | When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device.snapone · orvc · CWE-204 | Medium5.3 | — | 0.5% | May 22, 2023 |
21Monitor | CVE-2014-5615No exploit | The Snap Secure (aka com.exclaim.snapsecure.app) application 9.5 for Android does not verify X.509 certificates from SSL servers, which allosnapone · snap secure · CWE-310 | Medium5.4 | — | 0.3% | Sep 8, 2014 |
- CVE-2023-3124140Plan
Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.
CriticalCVSS 10.0No exploitEPSS 1%snapone · orvcMay 22, 2023
- CVE-2023-3124039Monitor
Snap One OvrC Pro versions prior to 7.2 have their own locally running web server accessible both from the local network and remotely.
CriticalCVSS 9.8No exploitEPSS 1%snapone · orvcMay 22, 2023
- CVE-2023-2838639Monitor
Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly.
CriticalCVSS 9.8No exploitEPSS 0%snapone · orvcMay 22, 2023
- CVE-2024-5038135Monitor
Missing Authentication for Critical Function in Snap One OVRC cloud
HighCVSS 8.8No exploitEPSS 1%snap one · ovrc cloudDec 2, 2024
- CVE-2024-5038034Monitor
Authentication Bypass by Spoofing in Snap One OVRC cloud
HighCVSS 8.7No exploitEPSS 1%snap one · ovrc cloudDec 2, 2024
- CVE-2023-2864930Monitor
The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it.
HighCVSS 7.5No exploitEPSS 1%snapone · orvcMay 22, 2023
- CVE-2023-3119330Monitor
Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers.
HighCVSS 7.5No exploitEPSS 0%snapone · orvcMay 22, 2023
- CVE-2023-2518328Monitor
In Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a new functionality app
HighCVSS 7.2No exploitEPSS 1%snapone · orvcMay 22, 2023
- CVE-2023-3124524Monitor
Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP
MediumCVSS 6.1No exploitEPSS 0%snapone · orvcMay 22, 2023
- CVE-2023-2841221Monitor
When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device.
MediumCVSS 5.3No exploitEPSS 0%snapone · orvcMay 22, 2023
- CVE-2014-561521Monitor
The Snap Secure (aka com.exclaim.snapsecure.app) application 9.5 for Android does not verify X.509 certificates from SSL servers, which allo
MediumCVSS 5.4No exploitEPSS 0%snapone · snap secureSep 8, 2014