"value":"Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior use a proprietary local area network (LAN) protocol that does not verify updates to the device. An attacker could upload a malformed update file to the device and execute arbitrary code."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-345 Insufficient Verification of Data Authenticity",
"value":"\n\n<p>Snap One has released the following updates for the affected products: </p><ul><li>Version <a target=\"_blank\" rel=\"nofollow\" href=\"https://app.ovrc.com/#/user-settings\">WB10.B929</a> (login required) </li></ul>\n\n<br>"
}
],
"value":"\nSnap One has released the following updates for the affected products: \n\n * Version WB10.B929 https://app.ovrc.com/#/user-settings \u00a0(login required) \n\n\n\n\n\n"
}
],
"credits":[
{
"lang":"en",
"value":"Uri Katz of Claroty Research reported these vulnerabilities to CISA. "