← Back

CVE-2022-3189

nvd nist
Published: Dec 21, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specially crafted PHP script could use parameters from a HTTP request to create a URL capable of changing the host parameter. The changed host parameter in the HTTP could point to another host that will send a request to the host or IP specified in the changed host parameter.

Affected (12)

12 products
Iboot Pdu4 N20 Firmware
Iboot Pdu4sa N15 Firmware
Iboot Pdu4a N15 Firmware
Iboot Pdu4sa N20 Firmware
Iboot Pdu4a N20 Firmware
Iboot Pdu8sa N15 Firmware
Iboot Pdu8a N15 Firmware
Iboot Pdu8sa 2n15 Firmware
Iboot Pdu8a 2n15 Firmware
Iboot Pdu8sa N20 Firmware
Iboot Pdu8a N20 Firmware
Iboot Pdu8a 2n20 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu4 N20
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu4sa N15
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu4a N15
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu4sa N20
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu4a N20
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu8sa N15
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu8a N15
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu8sa 2n15
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu8a 2n15
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu8sa N20
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu8a N20
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.42.06162022
Running on/withPlatform Versions
Dataprobe
Iboot Pdu8a 2n20
All versions

References (2)

Source: ics-cert@hq.dhs.gov
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource

Timeline

No history available yet.