ZeroHour

CVE-2023-33468

PoC
CVSS 3.1
9.1 critical
EPSS
<1%p53
Published
()
Modified
Description

KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, bypassing the need to obtain it directly from the physical screen.

Vendors
kramerav
Products
via go2 firmware, via connect2 firmware
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.