CVE-2023-33468

CRITICAL

KramerAV VIA Connect/VIA Go <4.0.1.1326 - RCE

Title source: llm
STIX 2.1

Description

KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, bypassing the need to obtain it directly from the physical screen.

References (2)

Core 2

Scores

CVSS v3 9.1
EPSS 0.0005
EPSS Percentile 15.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-863
Status published
Products (2)
kramerav/via_connect2_firmware < 4.0.1.1326
kramerav/via_go2_firmware < 4.0.1.1326
Published Aug 09, 2023
Tracked Since Feb 18, 2026