Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerability.



Advisories
Source ID Title
EUVD EUVD EUVD-2022-42600 Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerability.
Fixes

Solution

Dataprobe has released the following version update to mitigate these vulnerabilities: * iBoot-PDU FW: Version 1.42.06162022 https://dataprobe.com/support-iboot-pdu/ Dataprobe also recommends users to disable the SNMP if it is not in use.


Workaround

No workaround given by the vendor.

History

Tue, 15 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-04-15T19:36:19.949Z

Reserved: 2022-09-12T20:20:12.777Z

Link: CVE-2022-3183

cve-icon Vulnrichment

Updated: 2024-08-03T01:00:10.493Z

cve-icon NVD

Status : Modified

Published: 2022-12-21T23:15:09.393

Modified: 2024-11-21T07:18:59.637

Link: CVE-2022-3183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.