PT-2023-24349 · Kramerav · Kramerav Via Connect+1

Published

2023-08-09

·

Updated

2023-08-16

·

CVE-2023-33468

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions KramerAV VIA Connect (2) and VIA Go (2) versions prior to 4.0.1.1326
Description The issue allows for remote manipulation of the device by extracting the connection confirmation code remotely, bypassing the need to obtain it directly from the physical screen.
Recommendations For versions prior to 4.0.1.1326, update to version 4.0.1.1326 or later to resolve the issue.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-33468

Affected Products

Kramerav Via Connect
Kramerav Via Go²