Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly. The device only calculates the MD5 hash of the firmware and does not check using a private-public key mechanism. The lack of complete PKI system firmware signature could allow attackers to upload arbitrary firmware updates, resulting in code execution.
CVE ID: CVE-2023-28386
CVSS Base Severity: HIGH
CVSS Base Score: 8.6
Vendor: Snap One
Product: OvrC Cloud
EPSS Score: 0.39% (probability of being exploited)
EPSS Percentile: 73.19% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)