CVE-2023-25183: Snapone Orvc

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

In Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a new functionality appears that could allow users to execute arbitrary commands on the hub device.

Affected products

  • Snapone Orvc: before 7.3.0 (fixed in 7.3.0)

Published 2023-05-22. Last modified 2026-06-17.