CVE Published: 02/12/2024 |
CVE Updated: 02/12/2024 |
CVE Year: 2024 Source: icscert |
Vendor: Snap One |
Product: OVRC cloud Status : PUBLISHED
CVE-2024-50381 Description
A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and send requests to claim and unclaim devices. The attacker only needs to provide the MAC address of the targeted device and can make a request to unclaim it from its original connection and make a request to claim it.