Security Advisory

CVE-2023-31245

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-05-22 19:37:10
Last updated 2025-01-16 21:33:28
Assigner icscert
CVSS score 7.1
State PUBLISHED

Description

Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP connection. Attackers could impersonate a device and supply malicious information about the device’s web server interface. By supplying malicious parameters, an attacker could redirect the user to arbitrary and dangerous locations on the web.