Snapone's vulnerability footprint centers on a narrow portfolio of networked audio-visual control and remote-access products designed for residential and commercial integration, with exposure concentrated in devices such as the ORVC series and AN-110 networking appliances. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through weakness classes including cleartext transmission of sensitive information, hidden or undocumented functionality, improper input validation, and resource-locking flaws that are characteristic of embedded control and remote-management systems. Defenders should prioritize inventory and patching of these networked devices, particularly those exposed to untrusted networks; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Snapone over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28386CRITICAL Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly. The device only calculates the MD5 hash of the firmware and does not check using a priv | May 22, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-31241CRITICAL Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright. | May 22, 2023 | 10.0 | 30 | NO | NO |
CVE-2023-31240CRITICAL Snap One OvrC Pro versions prior to 7.2 have their own locally running web server accessible both from the local network and remotely. OvrC cloud contains a hidden superuser accoun | May 22, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-31193HIGH
Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers. Because they do not use HTTPS, OvrC Pro devices are suscept | May 22, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-28649HIGH The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it. A vulnerability exists in which an attacker could impersonate | May 22, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-25183HIGH
In Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a new functionality appears that could allow users to execute a | May 22, 2023 | 7.2 | 23 | NO | NO |
CVE-2023-28412MEDIUM
When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack an | May 22, 2023 | 5.3 | 19 | NO | NO |
CVE-2023-31245MEDIUM
Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP connection. Attackers could impersonate | May 22, 2023 | 6.1 | 17 | NO | NO |
CVE-2014-5615MEDIUM The Snap Secure (aka com.exclaim.snapsecure.app) application 9.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof | Sep 9, 2014 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Snapone.
Media articles that mention a CVE ID that affects a product developed by Snapone — matched by CVE ID, not by vendor name.