Записи snapone
11 опубликованных записей вендора snapone.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-1391 Use of Weak Credentials1
- CWE-204 Observable Response Discrepancy1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-306 Missing Authentication for Critical Function1
- CWE-310 Cryptographic Issues1
- CWE-319 Cleartext Transmission of Sensitive Information1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2023-31241Эксплойта нет | Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.snapone · orvc · CWE-420 | Критическая10,0 | — | 0,8 % | 22 мая 2023 г. |
39Наблюдать | CVE-2023-31240Эксплойта нет | Snap One OvrC Pro versions prior to 7.2 have their own locally running web server accessible both from the local network and remotely.snapone · orvc · CWE-1391 | Критическая9,8 | — | 0,5 % | 22 мая 2023 г. |
39Наблюдать | CVE-2023-28386Эксплойта нет | Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly.snapone · orvc · CWE-354 | Критическая9,8 | — | 0,4 % | 22 мая 2023 г. |
35Наблюдать | CVE-2024-50381Эксплойта нет | Missing Authentication for Critical Function in Snap One OVRC cloudsnap one · ovrc cloud · CWE-306 | Высокая8,8 | — | 0,5 % | 2 дек. 2024 г. |
34Наблюдать | CVE-2024-50380Эксплойта нет | Authentication Bypass by Spoofing in Snap One OVRC cloudsnap one · ovrc cloud · CWE-290 | Высокая8,7 | — | 0,5 % | 2 дек. 2024 г. |
30Наблюдать | CVE-2023-28649Эксплойта нет | The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it.snapone · orvc · CWE-413 | Высокая7,5 | — | 0,5 % | 22 мая 2023 г. |
30Наблюдать | CVE-2023-31193Эксплойта нет | Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers.snapone · orvc · CWE-319 | Высокая7,5 | — | 0,4 % | 22 мая 2023 г. |
28Наблюдать | CVE-2023-25183Эксплойта нет | In Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a new functionality appsnapone · orvc · CWE-912 | Высокая7,2 | — | 0,6 % | 22 мая 2023 г. |
24Наблюдать | CVE-2023-31245Эксплойта нет | Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP snapone · orvc · CWE-601 | Средняя6,1 | — | 0,4 % | 22 мая 2023 г. |
21Наблюдать | CVE-2023-28412Эксплойта нет | When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device.snapone · orvc · CWE-204 | Средняя5,3 | — | 0,5 % | 22 мая 2023 г. |
21Наблюдать | CVE-2014-5615Эксплойта нет | The Snap Secure (aka com.exclaim.snapsecure.app) application 9.5 for Android does not verify X.509 certificates from SSL servers, which allosnapone · snap secure · CWE-310 | Средняя5,4 | — | 0,3 % | 8 сент. 2014 г. |
- CVE-2023-3124140В плане
Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %snapone · orvc22 мая 2023 г.
- CVE-2023-3124039Наблюдать
Snap One OvrC Pro versions prior to 7.2 have their own locally running web server accessible both from the local network and remotely.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %snapone · orvc22 мая 2023 г.
- CVE-2023-2838639Наблюдать
Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %snapone · orvc22 мая 2023 г.
- CVE-2024-5038135Наблюдать
Missing Authentication for Critical Function in Snap One OVRC cloud
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %snap one · ovrc cloud2 дек. 2024 г.
- CVE-2024-5038034Наблюдать
Authentication Bypass by Spoofing in Snap One OVRC cloud
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %snap one · ovrc cloud2 дек. 2024 г.
- CVE-2023-2864930Наблюдать
The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %snapone · orvc22 мая 2023 г.
- CVE-2023-3119330Наблюдать
Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %snapone · orvc22 мая 2023 г.
- CVE-2023-2518328Наблюдать
In Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a new functionality app
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %snapone · orvc22 мая 2023 г.
- CVE-2023-3124524Наблюдать
Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP
СредняяCVSS 6,1Эксплойта нетEPSS 0 %snapone · orvc22 мая 2023 г.
- CVE-2023-2841221Наблюдать
When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device.
СредняяCVSS 5,3Эксплойта нетEPSS 0 %snapone · orvc22 мая 2023 г.
- CVE-2014-561521Наблюдать
The Snap Secure (aka com.exclaim.snapsecure.app) application 9.5 for Android does not verify X.509 certificates from SSL servers, which allo
СредняяCVSS 5,4Эксплойта нетEPSS 0 %snapone · snap secure8 сент. 2014 г.