CVE-2023-28412

When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack and the OvrC cloud will disclose their information.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:snapone:orvc:*:*:*:*:*:pro:*:*
OR cpe:2.3:h:control4:ca-1:-:*:*:*:*:*:*:*
cpe:2.3:h:control4:ca-10:-:*:*:*:*:*:*:*
cpe:2.3:h:control4:ea-1:-:*:*:*:*:*:*:*
cpe:2.3:h:control4:ea-3:-:*:*:*:*:*:*:*
cpe:2.3:h:control4:ea-5:-:*:*:*:*:*:*:*
cpe:2.3:h:snapone:an-110-rt-2l1w:-:*:*:*:*:*:*:*
cpe:2.3:h:snapone:an-110-rt-2l1w-wifi:-:*:*:*:*:*:*:*
cpe:2.3:h:snapone:an-310-rt-4l2w:-:*:*:*:*:*:*:*
cpe:2.3:h:snapone:ovrc-300-pro:-:*:*:*:*:*:*:*
cpe:2.3:h:snapone:pakedge_rk-1:-:*:*:*:*:*:*:*
cpe:2.3:h:snapone:pakedge_rt-3100:-:*:*:*:*:*:*:*
cpe:2.3:h:snapone:pakedge_wr-1:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-05-22 20:15

Updated : 2024-11-21 07:55


NVD link : CVE-2023-28412

Mitre link : CVE-2023-28412

CVE.ORG link : CVE-2023-28412


JSON object : View

Products Affected

control4

  • ca-1
  • ea-3
  • ea-1
  • ea-5
  • ca-10

snapone

  • orvc
  • an-110-rt-2l1w
  • pakedge_rt-3100
  • pakedge_wr-1
  • pakedge_rk-1
  • an-110-rt-2l1w-wifi
  • an-310-rt-4l2w
  • ovrc-300-pro
CWE
CWE-204

Observable Response Discrepancy

CWE-203

Observable Discrepancy