CVE-2022-4945
- EPSS 0.03%
- Veröffentlicht 22.05.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:36:18
The Dataprobe cloud usernames and passwords are stored in plain text in a specific file. Any user able to read this specific file from the device could compromise other devices connected to the user's cloud.
CVE-2022-3183
- EPSS 1.09%
- Veröffentlicht 21.12.2022 23:15:09
- Zuletzt bearbeitet 21.11.2024 07:18:59
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerability.
CVE-2022-3189
- EPSS 0.24%
- Veröffentlicht 21.12.2022 23:15:09
- Zuletzt bearbeitet 21.11.2024 07:19:00
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specially crafted PHP script could use parameters from a HTTP request to create a URL capable of changing the host parameter. The changed host parameter in the HTT...
CVE-2022-3188
- EPSS 0.16%
- Veröffentlicht 21.12.2022 23:15:09
- Zuletzt bearbeitet 21.11.2024 07:19:00
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where unauthenticated users could open PHP index pages without authentication and download the history file from the device; the history file includes the latest actions c...
CVE-2022-3187
- EPSS 0.14%
- Veröffentlicht 21.12.2022 23:15:09
- Zuletzt bearbeitet 21.11.2024 07:19:00
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is established with the database. However, these PHP pages do not verify the validity of a user. Attackers co...
CVE-2022-3186
- EPSS 0.17%
- Veröffentlicht 21.12.2022 23:15:09
- Zuletzt bearbeitet 21.11.2024 07:19:00
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the device’s main management page from the cloud. This feature enables users to remotely connect devices, however, ...
CVE-2022-3185
- EPSS 0.16%
- Veröffentlicht 21.12.2022 23:15:09
- Zuletzt bearbeitet 21.11.2024 07:18:59
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product exposes sensitive data concerning the device.
CVE-2022-3184
- EPSS 2.1%
- Veröffentlicht 21.12.2022 23:15:09
- Zuletzt bearbeitet 21.11.2024 07:18:59
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to access an old PHP page vulnerable to directory traversal, which may allow a user to write a file to th...