Orvc
Vendor:
First CVE: May 22, 2023 · Active for 3 years
8
Total CVEs
More Total CVEs than 85% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Orvc over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 22, 2023
3 years ago
Most Recent CVE
May 22, 2023
1,159 days ago
CVE Severity & Scoring
Orvc8 CVEs
25%
38%
38%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (87.5%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low0 (0.0%)
High1 (12.5%)
None7 (87.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28386CRITICAL Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly. The device only calculates the MD5 hash of the firmware and does not check using a priv | May 22, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-31241CRITICAL Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright. | May 22, 2023 | 10.0 | 30 | NO | NO |
CVE-2023-31240CRITICAL Snap One OvrC Pro versions prior to 7.2 have their own locally running web server accessible both from the local network and remotely. OvrC cloud contains a hidden superuser accoun | May 22, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-31193HIGH
Snap One OvrC Pro versions prior to 7.3 use HTTP connections when downloading a program from their servers. Because they do not use HTTPS, OvrC Pro devices are suscept | May 22, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-28649HIGH The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it. A vulnerability exists in which an attacker could impersonate | May 22, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-25183HIGH
In Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a new functionality appears that could allow users to execute a | May 22, 2023 | 7.2 | 23 | NO | NO |
CVE-2023-28412MEDIUM
When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack an | May 22, 2023 | 5.3 | 19 | NO | NO |
CVE-2023-31245MEDIUM
Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP connection. Attackers could impersonate | May 22, 2023 | 6.1 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Orvc
Top CWEs
Versions
No cataloged versions.