Snapav manufactures the WattBox IP power-management appliance line, a narrowly focused product portfolio for networked infrastructure monitoring and control. Vulnerabilities in this vendor's disclosures center on memory-safety issues such as heap-based buffer overflows and out-of-bounds writes, alongside authentication and data-integrity weaknesses including insufficient verification of data authenticity and plaintext password storage. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Snapav over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24020CRITICAL
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior could bypass the brute force protection, allowing multiple attempts to force a login.
| Jan 30, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-23582CRITICAL
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior are vulnerable to a heap-based buffer overflow, which could allow an attacker to execute arbitrary code or crash the devi | Jan 30, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-22315HIGH
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior use a proprietary local area network (LAN) protocol that does not verify updates to the device. An attacker could upload | Jan 30, 2023 | 7.8 | 25 | NO | NO |
CVE-2023-22389MEDIUM
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior store passwords in a plaintext file when the device configuration is exported via Save/Restore–>Backup Settings, which co | Jan 30, 2023 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Snapav.
Media articles that mention a CVE ID that affects a product developed by Snapav — matched by CVE ID, not by vendor name.