Dataprobe
Dataprobe Iboot-pdu4sa-c10 Firmware: vulnerabilidades y CVE
Dataprobe Iboot-pdu4sa-c10 Firmware tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-3264 | Crítica (9.8) | 0.47% | — | 14 ago 2023 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database. A malicious agent with the ability to execute operating… |
| CVE-2023-3263 | Alta (7.5) | 0.69% | — | 14 ago 2023 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the mishandling of special characters when parsing credentials.Successful… |
| CVE-2023-3262 | Media (6.7) | 0.30% | — | 14 ago 2023 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database.A malicious agent with the ability to execute operating… |
| CVE-2023-3261 | Alta (7.2) | 0.78% | — | 14 ago 2023 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Successful exploitation could cause denial of service or unexpected… |
| CVE-2023-3260 | Alta (8.8) | 1.3% | — | 14 ago 2023 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute… |
| CVE-2023-3259 | Crítica (9.8) | 0.95% | — | 14 ago 2023 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By manipulating the IP address field in the "iBootPduSiteAuth" cookie, a malicious agent can direct the… |
| CVE-2022-47320 | Alta (8.1) | 0.51% | — | 22 may 2023 | The iBoot device’s basic discovery protocol assists in initial device configuration. The discovery protocol shows basic information about devices on the network and allows users to perform configuration changes. |
| CVE-2022-47311 | Alta (8.8) | 0.52% | — | 22 may 2023 | A proprietary protocol for iBoot devices is used for control and keepalive commands. The function compares the username and password; it also contains the configuration data for the user specified. If the user does not… |
| CVE-2022-46738 | Crítica (9.8) | 0.58% | — | 22 may 2023 | The affected product exposes multiple sensitive data fields of the affected product. An attacker can use the SNMP command to get device mac address and login as admin. |
| CVE-2022-46658 | Crítica (9.8) | 1.2% | — | 22 may 2023 | The affected product is vulnerable to a stack-based buffer overflow which could lead to a denial of service or remote code execution. |
| CVE-2022-4945 | Media (6.5) | 0.17% | — | 22 may 2023 | The Dataprobe cloud usernames and passwords are stored in plain text in a specific file. Any user able to read this specific file from the device could compromise other devices connected to the user's cloud. |
Otros productos de Dataprobe
Iboot-pdu8a-2n20 Firmware · 18Iboot-pdu4-n20 Firmware · 18Iboot-pdu4sa-n15 Firmware · 18Iboot-pdu8a-n15 Firmware · 18Iboot-pdu8a-n20 Firmware · 18Iboot-pdu8sa-2n15 Firmware · 18Iboot-pdu4sa-n20 Firmware · 18Iboot-pdu8sa-n15 Firmware · 18Iboot-pdu8sa-n20 Firmware · 18Iboot-pdu4a-n15 Firmware · 18Iboot-pdu4a-n20 Firmware · 18Iboot-pdu8a-2n15 Firmware · 18