5.3
CVE-2022-3189
- EPSS 0.24%
- Veröffentlicht 21.12.2022 23:15:09
- Zuletzt bearbeitet 21.11.2024 07:19:00
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specially crafted PHP script could use parameters from a HTTP request to create a URL capable of changing the host parameter. The changed host parameter in the HTTP could point to another host that will send a request to the host or IP specified in the changed host parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dataprobe ≫ Iboot-pdu4-n20 Firmware Version < 1.42.06162022
Dataprobe ≫ Iboot-pdu4sa-n15 Firmware Version < 1.42.06162022
Dataprobe ≫ Iboot-pdu4a-n15 Firmware Version < 1.42.06162022
Dataprobe ≫ Iboot-pdu4sa-n20 Firmware Version < 1.42.06162022
Dataprobe ≫ Iboot-pdu4a-n20 Firmware Version < 1.42.06162022
Dataprobe ≫ Iboot-pdu8sa-n15 Firmware Version < 1.42.06162022
Dataprobe ≫ Iboot-pdu8a-n15 Firmware Version < 1.42.06162022
Dataprobe ≫ Iboot-pdu8sa-2n15 Firmware Version < 1.42.06162022
Dataprobe ≫ Iboot-pdu8a-2n15 Firmware Version < 1.42.06162022
Dataprobe ≫ Iboot-pdu8sa-n20 Firmware Version < 1.42.06162022
Dataprobe ≫ Iboot-pdu8a-n20 Firmware Version < 1.42.06162022
Dataprobe ≫ Iboot-pdu8a-2n20 Firmware Version < 1.42.06162022
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.466 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
| ics-cert@hq.dhs.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.