Skip to main content

CVE-2023-31241

8.6
HIGHCVSS v3.1 Base Score
0.01%
LOW RiskEPSS (2nd percentile)

Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.

Published: 5/22/2023
Modified: 12/9/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

EPSS Score (Exploitation Probability)

0.01%LOW Exploitation Risk
2nd percentile

This vulnerability has a 0.01% probability of being exploited in the next 30 days, ranking higher than 2% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-420)

CVE-2025-54309CRITICAL 9

CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.

7/18/2025
CVE-2024-10081CRITICAL 10

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the API URL ends with Authentication. This bypass allows superuser access to all API endpoints other than Authentication. These endpoints include the ability to add, edit, and remove products, among others. All endpoints, apart from the /Authentication is affected by the vulnerability. This issue affects CodeChecker: through 6.24.1.

11/6/2024
CVE-2023-20198CRITICAL 10

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343.

10/16/2023

Similar SeverityHIGH