Missing Authentication for Critical Function in Snap One OVRC cloud
Vulnerability Description
A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and send requests to claim and unclaim devices. The attacker only needs to provide the MAC address of the targeted device and can make a request to unclaim it from its original connection and make a request to claim it.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-50381
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Uri Katz of Claroty reported these vulnerabilities to CISA.
More from Snap One
View All →Affected Vendor
Snap One
View all reports →