CVE-2023-31241
Snapone Orvc ≤ 7.3.0
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HSummary
CVE-2023-31241 is a high-severity Unprotected Alternate Channel (CWE-420) vulnerability in Snapone Orvc. Its CVSS base score is 8.6 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Fallback Channels (T1008); ranked in the top 48% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-35556
Vulnerability Data
Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Usage restrictions and authorization for remote access protect against unprotected alternate channels.
TSCM surveys detect and neutralize unprotected alternate channels introduced by surveillance equipment or modifications.
Removes or disables unprotected alternate I/O channels that could otherwise be used to bypass primary controls.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Protecting all data-in-transit directly mitigates unequal channel protection though the control addresses broader transit scenarios.
Network protection from unauthorized access inherently requires securing every channel, not just primaries.
Network monitoring can surface use of unprotected alternate channels but does not prevent the design flaw.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Access restrictions may cover primary paths but leave alternate channels unprotected unless explicitly extended.
Secure authentication applies to primary channels but does not ensure alternate channels receive the same strength.
Network security controls ensure all channels receive equivalent protection, directly addressing unprotected alternate channels.
Security of network services requires consistent protection across all service channels, mitigating alternate-channel weaknesses.
Network segregation can reduce exposure of alternate channels but does not guarantee equivalent protection levels.
Cryptography can protect alternate channels but does not address the policy of applying equal protection across channels.