CVE-2023-3261
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD
Description
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Successful exploitation could cause denial of service or unexpected behavior with respect to all interactions relying on the targeted vulnerable binary, including the ability to log in via the web server.
Affected (23)
Products: Cyberpower: Powerpanel Server · Dataprobe: Iboot Pdu4a C10 Firmware, Iboot Pdu4a C20 Firmware, Iboot Pdu4a N15 Firmware, Iboot Pdu4a N20 Firmware, Iboot Pdu4 C20 Firmware, Iboot Pdu4 N20 Firmware, Iboot Pdu4sa C10 Firmware, Iboot Pdu4sa C20 Firmware, Iboot Pdu4sa N15 Firmware, Iboot Pdu4sa N20 Firmware, Iboot Pdu8a 2c10 Firmware, Iboot Pdu8a 2c20 Firmware, Iboot Pdu8a 2n15 Firmware, Iboot Pdu8a 2n20 Firmware, Iboot Pdu8a C10 Firmware, Iboot Pdu8a C20 Firmware, Iboot Pdu8a N15 Firmware, Iboot Pdu8a N20 Firmware, Iboot Pdu8sa 2n15 Firmware, Iboot Pdu8sa C10 Firmware, Iboot Pdu8sa N15 Firmware, Iboot Pdu8sa N20 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.9 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu4a C10 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu4a C20 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu4a N15 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu4a N20 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu4 C20 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu4 N20 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu4sa C10 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu4sa C20 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu4sa N15 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu4sa N20 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu8a 2c10 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu8a 2c20 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu8a 2n15 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu8a 2n20 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu8a C10 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu8a C20 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu8a N15 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu8a N20 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu8sa 2n15 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu8sa C10 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu8sa N15 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.44.0804202 |
| Running on/with | Platform Versions |
|---|---|
Dataprobe Iboot Pdu8sa N20 | All versions |
Related CWEs
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
References (2)
Source: trellixpsirt@trellix.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.