CVE-2023-31245

CVSS V2 None CVSS V3 None
Description
Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP connection. Attackers could impersonate a device and supply malicious information about the device’s web server interface. By supplying malicious parameters, an attacker could redirect the user to arbitrary and dangerous locations on the web.
Overview
  • CVE ID
  • CVE-2023-31245
  • Assigner
  • ics-cert@hq.dhs.gov
  • Vulnerability Status
  • Received
  • Published Version
  • 2023-05-22T20:15:10
  • Last Modified Date
  • 2023-05-22T20:15:10
History
Created Old Value New Value Data Type Notes
2023-05-22 21:00:36 Added to TrackCVE
2023-05-22 21:00:40 Weakness Enumeration new