CVE-2022-3186
—CVSS 3.1
7.5 high
EPSS
<1%p45
Published
()
Modified
Description
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the device’s main management page from the cloud. This feature enables users to remotely connect devices, however, the current implementation permits users to access other device's information.
- Vendors
- dataprobe
- Products
- iboot-pdu4-n20 firmware, iboot-pdu4sa-n15 firmware, iboot-pdu4a-n15 firmware, iboot-pdu4sa-n20 firmware, iboot-pdu4a-n20 firmware, iboot-pdu8sa-n15 firmware, iboot-pdu8a-n15 firmware, iboot-pdu8sa-2n15 firmware, iboot-pdu8a-2n15 firmware, iboot-pdu8sa-n20 firmware, iboot-pdu8a-n20 firmware, iboot-pdu8a-2n20 firmware
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.