Description
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to access an old PHP page vulnerable to directory traversal, which may allow a user to write a file to the webroot directory.





Published: 2022-12-21
Score: 9.8 Critical
EPSS: 2.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Dataprobe has released the following version update to mitigate these vulnerabilities: * iBoot-PDU FW: Version 1.42.06162022 https://dataprobe.com/support-iboot-pdu/ Dataprobe also recommends users to disable the SNMP if it is not in use.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Dataprobe Iboot-pdu4-n20 Iboot-pdu4-n20 Firmware Iboot-pdu4a-n15 Iboot-pdu4a-n15 Firmware Iboot-pdu4a-n20 Iboot-pdu4a-n20 Firmware Iboot-pdu4sa-n15 Iboot-pdu4sa-n15 Firmware Iboot-pdu4sa-n20 Iboot-pdu4sa-n20 Firmware Iboot-pdu8a-2n15 Iboot-pdu8a-2n15 Firmware Iboot-pdu8a-2n20 Iboot-pdu8a-2n20 Firmware Iboot-pdu8a-n15 Iboot-pdu8a-n15 Firmware Iboot-pdu8a-n20 Iboot-pdu8a-n20 Firmware Iboot-pdu8sa-2n15 Iboot-pdu8sa-2n15 Firmware Iboot-pdu8sa-n15 Iboot-pdu8sa-n15 Firmware Iboot-pdu8sa-n20 Iboot-pdu8sa-n20 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-04-15T19:35:52.739Z

Reserved: 2022-09-12T20:21:46.134Z

Link: CVE-2022-3184

cve-icon Vulnrichment

Updated: 2024-08-03T01:00:10.589Z

cve-icon NVD

Status : Modified

Published: 2022-12-21T23:15:09.517

Modified: 2024-11-21T07:18:59.787

Link: CVE-2022-3184

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses