📦 Orvc

by Snapone

🔍 What is Orvc?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-28386

HIGH CVSS 8.6 May 22, 2023

This vulnerability allows attackers to upload malicious firmware to Snap One OvrC Pro devices due to insufficient signature validation. Only MD5 hash checking is performed instead of proper PKI-based ...

CVE-2023-28649

HIGH CVSS 8.6 May 22, 2023

This vulnerability in Snap One OvrC cloud platform allows attackers to impersonate a hub and send device requests to claim already claimed devices. The cloud platform fails to validate if devices are ...

CVE-2023-31193

HIGH CVSS 7.5 May 22, 2023

Snap One OvrC Pro devices prior to version 7.3 download programs over unencrypted HTTP connections instead of HTTPS, making them vulnerable to man-in-the-middle attacks. This affects all OvrC Pro devi...

CVE-2023-31241

HIGH CVSS 8.6 May 22, 2023

This vulnerability in Snap One OvrC cloud servers allows attackers to bypass security requirements and claim devices without authorization, potentially taking control of connected IoT devices. It affe...