Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to access an old PHP page vulnerable to directory traversal, which may allow a user to write a file to the webroot directory.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDataprobe Iboot Pdu4a N15
HWDataprobeall versionsDataprobe Iboot Pdu4a N15 Firmware
OSDataprobe< 1.42.06162022Dataprobe Iboot Pdu4a N20
HWDataprobeall versionsDataprobe Iboot Pdu4a N20 Firmware
OSDataprobe< 1.42.06162022Dataprobe Iboot Pdu4 N20
HWDataprobeall versionsDataprobe Iboot Pdu4 N20 Firmware
OSDataprobe< 1.42.06162022Dataprobe Iboot Pdu4sa N15
HWDataprobeall versionsDataprobe Iboot Pdu4sa N15 Firmware
OSDataprobe< 1.42.06162022Dataprobe Iboot Pdu4sa N20
HWDataprobeall versionsDataprobe Iboot Pdu4sa N20 Firmware
OSDataprobe< 1.42.06162022Dataprobe Iboot Pdu8a 2n15
HWDataprobeall versionsDataprobe Iboot Pdu8a 2n15 Firmware
OSDataprobe< 1.42.06162022Dataprobe Iboot Pdu8a 2n20
HWDataprobeall versionsDataprobe Iboot Pdu8a 2n20 Firmware
OSDataprobe< 1.42.06162022Dataprobe Iboot Pdu8a N15
HWDataprobeall versionsDataprobe Iboot Pdu8a N15 Firmware
OSDataprobe< 1.42.06162022Dataprobe Iboot Pdu8a N20
HWDataprobeall versionsDataprobe Iboot Pdu8a N20 Firmware
OSDataprobe< 1.42.06162022Dataprobe Iboot Pdu8sa 2n15
HWDataprobeall versionsDataprobe Iboot Pdu8sa 2n15 Firmware
OSDataprobe< 1.42.06162022Dataprobe Iboot Pdu8sa N15
HWDataprobeall versionsDataprobe Iboot Pdu8sa N15 Firmware
OSDataprobe< 1.42.06162022Dataprobe Iboot Pdu8sa N20
HWDataprobeall versionsDataprobe Iboot Pdu8sa N20 Firmware
OSDataprobe< 1.42.06162022
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
Related vulnerabilities
CVE-2023-3259CRITICAL9.8PL ✓same product
Authentication bypass przez manipulację cookie w Dataprobe iBoot PDU
CVE-2022-3183CRITICAL9.8PL ✓same product
Command injection w firmware urządzeń Dataprobe iBoot-PDU
CVE-2023-3261HIGH7.5same product
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerabi...
CVE-2023-3260HIGH7.2same product
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection v...
CVE-2023-3263HIGH7.5same product
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypa...