ZeroHour

CVE-2023-3260

CVSS 3.1
8.8 high
EPSS
1%p68
Published
()
Modified
Description

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute arbitrary command on the underlying Linux operating system.

Vendors
cyberpowerdataprobe
Products
powerpanel server, iboot-pdu4a-c10 firmware, iboot-pdu4a-c20 firmware, iboot-pdu4a-n15 firmware, iboot-pdu4a-n20 firmware, iboot-pdu4-c20 firmware, iboot-pdu4-n20 firmware, iboot-pdu4sa-c10 firmware, iboot-pdu4sa-c20 firmware, iboot-pdu4sa-n15 firmware, iboot-pdu4sa-n20 firmware, iboot-pdu8a-2c10 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news