Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Snapone

First CVE: Sep 9, 2014Active for: 12 yearsTotal CVEs: 9

Snapone's vulnerability footprint centers on a narrow portfolio of networked audio-visual control and remote-access products designed for residential and commercial integration, with exposure concentrated in devices such as the ORVC series and AN-110 networking appliances. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through weakness classes including cleartext transmission of sensitive information, hidden or undocumented functionality, improper input validation, and resource-locking flaws that are characteristic of embedded control and remote-management systems. Defenders should prioritize inventory and patching of these networked devices, particularly those exposed to untrusted networks; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Snapone over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 9, 2014
11 years ago
Most Recent CVE
May 22, 2023
1,160 days ago

Products(9 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-28386CRITICAL
Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly. The device only calculates the MD5 hash of the firmware and does not check using a priv
May 22, 20239.831NONO
CVE-2023-31241CRITICAL
Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.
May 22, 202310.030NONO
CVE-2023-31240CRITICAL
Snap One OvrC Pro versions prior to 7.2 have their own locally running web server accessible both from the local network and remotely. OvrC cloud contains a hidden superuser accoun
May 22, 20239.830NONO
CVE-2023-31193HIGH
Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers. Because they do not use HTTPS, OvrC Pro devices are suscept
May 22, 20237.524NONO
CVE-2023-28649HIGH
The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it. A vulnerability exists in which an attacker could impersonate
May 22, 20237.524NONO
CVE-2023-25183HIGH
In Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a new functionality appears that could allow users to execute a
May 22, 20237.223NONO
CVE-2023-28412MEDIUM
When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack an
May 22, 20235.319NONO
CVE-2023-31245MEDIUM
Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP connection. Attackers could impersonate
May 22, 20236.117NONO
CVE-2014-5615MEDIUM
The Snap Secure (aka com.exclaim.snapsecure.app) application 9.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof
Sep 9, 20145.417NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
33%
33%
33%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (88.9%)
Unknown1 (11.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High0 (0.0%)
Unknown1 (11.1%)
User Interaction
None7 (77.8%)
Unknown1 (11.1%)
Required1 (11.1%)
Privileges Required
Low0 (0.0%)
High1 (11.1%)
None7 (77.8%)
Unknown1 (11.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Snapone.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Snapone — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Snapone's Products

View all 2 CNAs →

Top CWEs