CVE-2023-28412 Information

Description

When supplied with a random MAC address Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack and the OvrC cloud will disclose their information.

Reference

https://www.cisa.gov/news-events/ics-advisories/icsa-23-136-01 https://www.control4.com/docs/product/ovrc-software/release-notes/english/latest/ovrc-software-release-notes-rev-r.pdf

Share on: