NA

CVE-2023-3264

Published: 14/08/2023 Updated: 25/08/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database. A malicious agent with the ability to execute operating system commands on the device can leverage this vulnerability to read, modify, or delete arbitrary database records.

Vulnerable Product Search on Vulmon Subscribe to Product

cyberpower powerpanel server

dataprobe iboot-pdu4a-c10_firmware

dataprobe iboot-pdu4a-c20_firmware

dataprobe iboot-pdu4a-n15_firmware

dataprobe iboot-pdu4a-n20_firmware

dataprobe iboot-pdu4-c20_firmware

dataprobe iboot-pdu4-n20_firmware

dataprobe iboot-pdu4sa-c10_firmware

dataprobe iboot-pdu4sa-c20_firmware

dataprobe iboot-pdu4sa-n15_firmware

dataprobe iboot-pdu4sa-n20_firmware

dataprobe iboot-pdu8a-2c10_firmware

dataprobe iboot-pdu8a-2c20_firmware

dataprobe iboot-pdu8a-2n15_firmware

dataprobe iboot-pdu8a-2n20_firmware

dataprobe iboot-pdu8a-c10_firmware

dataprobe iboot-pdu8a-c20_firmware

dataprobe iboot-pdu8a-n15_firmware

dataprobe iboot-pdu8a-n20_firmware

dataprobe iboot-pdu8sa-2n15_firmware

dataprobe iboot-pdu8sa-c10_firmware

dataprobe iboot-pdu8sa-n15_firmware

dataprobe iboot-pdu8sa-n20_firmware