Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the device’s main management page from the cloud. This feature enables users to remotely connect devices, however, the current implementation permits users to access other device's information.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-42603 Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the device’s main management page from the cloud. This feature enables users to remotely connect devices, however, the current implementation permits users to access other device's information.
Fixes

Solution

Dataprobe has released the following version update to mitigate these vulnerabilities: * iBoot-PDU FW: Version 1.42.06162022 https://dataprobe.com/support-iboot-pdu/ Dataprobe also recommends users to disable the SNMP if it is not in use.


Workaround

No workaround given by the vendor.

History

Tue, 15 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-04-15T19:34:02.557Z

Reserved: 2022-09-12T20:22:40.302Z

Link: CVE-2022-3186

cve-icon Vulnrichment

Updated: 2024-08-03T01:00:10.684Z

cve-icon NVD

Status : Modified

Published: 2022-12-21T23:15:09.697

Modified: 2024-11-21T07:19:00.090

Link: CVE-2022-3186

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.