Control4 manufactures home and building automation controllers such as the CA-1, CA-10, and EA-1 series, which serve as central hubs for lighting, climate, security, and entertainment integration. Its vulnerability profile centers on authentication and data-integrity weaknesses in firmware and protocol handling, including improper validation of integrity checks and insufficient verification of data authenticity, which reflect the trust and verification demands of networked control systems. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Control4 over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28386CRITICAL Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly. The device only calculates the MD5 hash of the firmware and does not check using a priv | May 22, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-31241CRITICAL Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright. | May 22, 2023 | 10.0 | 30 | NO | NO |
CVE-2023-28412MEDIUM
When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack an | May 22, 2023 | 5.3 | 19 | NO | NO |
CVE-2023-31245MEDIUM
Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP connection. Attackers could impersonate | May 22, 2023 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Control4.
Media articles that mention a CVE ID that affects a product developed by Control4 — matched by CVE ID, not by vendor name.