CVE-2024-50381: Snap One Ovrc Cloud

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and send requests to claim and unclaim devices. The attacker only needs to provide the MAC address of the targeted device and can make a request to unclaim it from its original connection and make a request to claim it.

Affected products

  • Snap One Ovrc Cloud: before 7.3 (fixed in 7.3)
  • Snapone Ovrc-300-Pro: before 7.3 (fixed in 7.3)

Published 2024-12-02. Last modified 2026-06-17.