CVE-2022-3187
—CVSS 3.1
5.3 medium
EPSS
<1%p38
Published
()
Modified
Description
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is established with the database. However, these PHP pages do not verify the validity of a user. Attackers could leverage this lack of verification to read the state of outlets.
- Vendors
- dataprobe
- Products
- iboot-pdu4-n20 firmware, iboot-pdu4sa-n15 firmware, iboot-pdu4a-n15 firmware, iboot-pdu4sa-n20 firmware, iboot-pdu4a-n20 firmware, iboot-pdu8sa-n15 firmware, iboot-pdu8a-n15 firmware, iboot-pdu8sa-2n15 firmware, iboot-pdu8a-2n15 firmware, iboot-pdu8sa-n20 firmware, iboot-pdu8a-n20 firmware, iboot-pdu8a-2n20 firmware
- Weakness
- CWE-285
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.