CVE-2023-22315

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
30/01/2023
Last modified:
07/11/2023

Description

<br /> Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior use a proprietary local area network (LAN) protocol that does not verify updates to the device. An attacker could upload a malformed update file to the device and execute arbitrary code. <br /> <br /> <br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:snapav:wattbox_wb-300-ip-3_firmware:*:*:*:*:*:*:*:* wb10.9a17 (including)
cpe:2.3:h:snapav:wattbox_wb-300-ip-3:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools