VendorsDataprobeiboot-pdu8sa-n15_firmwareall versions
Vulnerabilities

Dataprobe iBoot-PDU8SA-N15 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2022-3184
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to access an old PHP page vulnerable to directory traversal, which may allow a user to write a file to the webroot directory.
Published 2022-12-21 · Modified
9.8EPSS 0.116
CVE-2022-3183
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerability.
Published 2022-12-21 · Modified
9.8EPSS 0.016
CVE-2022-46658
CVE-2022-46658
Published 2023-05-22 · Modified
9.8EPSS 0.012
CVE-2023-3259
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By manipulating the IP address field in the "iBootPduSiteAuth" cookie, a malicious agent can direct the device to connect to a rouge database.Successful exploitation allows the malicious agent to take actions with administrator privileges including, but not limited to, manipulating power levels, modifying user accounts, and exporting confidential user information
Published 2023-08-14 · Modified
9.8EPSS 0.010
CVE-2022-46738
CVE-2022-46738
Published 2023-05-22 · Modified
9.8EPSS 0.006
CVE-2023-3264
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database. A malicious agent with the ability to execute operating system commands on the device can leverage this vulnerability to read, modify, or delete arbitrary database records.
Published 2023-08-14 · Modified
9.8EPSS 0.005
CVE-2023-3260
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute arbitrary command on the underlying Linux operating system.
Published 2023-08-14 · Modified
8.8EPSS 0.013
CVE-2022-47311
CVE-2022-47311
Published 2023-05-22 · Modified
8.8EPSS 0.005
CVE-2022-3186
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the device’s main management page from the cloud. This feature enables users to remotely connect devices, however, the current implementation permits users to access other device's information.
Published 2022-12-21 · Modified
8.6EPSS 0.006
CVE-2022-47320
CVE-2022-47320
Published 2023-05-22 · Modified
8.1EPSS 0.005
CVE-2023-3261
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Successful exploitation could cause denial of service or unexpected behavior with respect to all interactions relying on the targeted vulnerable binary, including the ability to log in via the web server.
Published 2023-08-14 · Modified
7.5EPSS 0.008
CVE-2023-3263
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the mishandling of special characters when parsing credentials.Successful exploitation allows the malicious agent to obtain a valid authorization token and read information relating to the state of the relays and power distribution.
Published 2023-08-14 · Modified
7.5EPSS 0.007
CVE-2023-3262
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database.A malicious agent with the ability to execute operating system commands on the device can leverage this vulnerability to read, modify, or delete arbitrary database records.
Published 2023-08-14 · Modified
6.7EPSS 0.003
CVE-2022-4945
CVE-2022-4945
Published 2023-05-22 · Modified
6.5EPSS 0.002
CVE-2022-3188
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where unauthenticated users could open PHP index pages without authentication and download the history file from the device; the history file includes the latest actions completed by specific users.
Published 2022-12-21 · Modified
5.3EPSS 0.005
CVE-2022-3189
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specially crafted PHP script could use parameters from a HTTP request to create a URL capable of changing the host parameter. The changed host parameter in the HTTP could point to another host that will send a request to the host or IP specified in the changed host parameter.
Published 2022-12-21 · Modified
5.3EPSS 0.005
CVE-2022-3185
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product exposes sensitive data concerning the device.
Published 2022-12-21 · Modified
5.3EPSS 0.005
CVE-2022-3187
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is established with the database. However, these PHP pages do not verify the validity of a user. Attackers could leverage this lack of verification to read the state of outlets.
Published 2022-12-21 · Modified
5.3EPSS 0.005