← Back

CVE-2022-3186

nvd nist
Published: Dec 21, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the device’s main management page from the cloud. This feature enables users to remotely connect devices, however, the current implementation permits users to access other device's information.

Affected (12)

12 products
Iboot Pdu4 N20 Firmware
Iboot Pdu4sa N15 Firmware
Iboot Pdu4a N15 Firmware
Iboot Pdu4sa N20 Firmware
Iboot Pdu4a N20 Firmware
Iboot Pdu8sa N15 Firmware
Iboot Pdu8a N15 Firmware
Iboot Pdu8sa 2n15 Firmware
Iboot Pdu8a 2n15 Firmware
Iboot Pdu8sa N20 Firmware
Iboot Pdu8a N20 Firmware
Iboot Pdu8a 2n20 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu4 N20
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu4sa N15
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu4a N15
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu4sa N20
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu4a N20
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu8sa N15
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu8a N15
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu8sa 2n15
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu8a 2n15
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu8sa N20
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu8a N20
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu8a 2n20
All versions

References (2)

Source: ics-cert@hq.dhs.gov
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource

Timeline

No history available yet.