5.3

CVE-2022-3189

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specially crafted PHP script could use parameters from a HTTP request to create a URL capable of changing the host parameter. The changed host parameter in the HTTP could point to another host that will send a request to the host or IP specified in the changed host parameter.



 



Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DataprobeIboot-pdu4-n20 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu4-n20 Version-
DataprobeIboot-pdu4sa-n15 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu4sa-n15 Version-
DataprobeIboot-pdu4a-n15 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu4a-n15 Version-
DataprobeIboot-pdu4sa-n20 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu4sa-n20 Version-
DataprobeIboot-pdu4a-n20 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu4a-n20 Version-
DataprobeIboot-pdu8sa-n15 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu8sa-n15 Version-
DataprobeIboot-pdu8a-n15 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu8a-n15 Version-
DataprobeIboot-pdu8sa-2n15 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu8sa-2n15 Version-
DataprobeIboot-pdu8a-2n15 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu8a-2n15 Version-
DataprobeIboot-pdu8sa-n20 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu8sa-n20 Version-
DataprobeIboot-pdu8a-n20 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu8a-n20 Version-
DataprobeIboot-pdu8a-2n20 Firmware Version < 1.42.06162022
   DataprobeIboot-pdu8a-2n20 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.466
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
ics-cert@hq.dhs.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.