Логотип exploitDog
bind:CVE-2023-28386
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-28386

Количество 2

Количество 2

nvd логотип

CVE-2023-28386

больше 2 лет назад

Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly. The device only calculates the MD5 hash of the firmware and does not check using a private-public key mechanism. The lack of complete PKI system firmware signature could allow attackers to upload arbitrary firmware updates, resulting in code execution.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-pvcj-xvm2-wgmw

больше 2 лет назад

Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly. The device only calculates the MD5 hash of the firmware and does not check using a private-public key mechanism. The lack of complete PKI system firmware signature could allow attackers to upload arbitrary firmware updates, resulting in code execution.

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-28386

Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly. The device only calculates the MD5 hash of the firmware and does not check using a private-public key mechanism. The lack of complete PKI system firmware signature could allow attackers to upload arbitrary firmware updates, resulting in code execution.

CVSS3: 8.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-pvcj-xvm2-wgmw

Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly. The device only calculates the MD5 hash of the firmware and does not check using a private-public key mechanism. The lack of complete PKI system firmware signature could allow attackers to upload arbitrary firmware updates, resulting in code execution.

CVSS3: 8.6
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу