8.6

CVE-2022-3186

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the device’s main management page from the cloud. This feature enables users to remotely connect devices, however, the current implementation permits users to access other device's information.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DataprobeIboot-pdu4-n20 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu4-n20 Version-
DataprobeIboot-pdu4sa-n15 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu4sa-n15 Version-
DataprobeIboot-pdu4a-n15 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu4a-n15 Version-
DataprobeIboot-pdu4sa-n20 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu4sa-n20 Version-
DataprobeIboot-pdu4a-n20 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu4a-n20 Version-
DataprobeIboot-pdu8sa-n15 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu8sa-n15 Version-
DataprobeIboot-pdu8a-n15 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu8a-n15 Version-
DataprobeIboot-pdu8sa-2n15 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu8sa-2n15 Version-
DataprobeIboot-pdu8a-2n15 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu8a-2n15 Version-
DataprobeIboot-pdu8sa-n20 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu8sa-n20 Version-
DataprobeIboot-pdu8a-n20 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu8a-n20 Version-
DataprobeIboot-pdu8a-2n20 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu8a-2n20 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.382
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
ics-cert@hq.dhs.gov 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.