Vulnerability Details CVE-2022-3187
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is established with the database. However, these PHP pages do not verify the validity of a user. Attackers could leverage this lack of verification to read the state of outlets.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 25.9%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2022-3187
-
cpe:2.3:h:dataprobe:iboot-pdu4-n20:-
-
cpe:2.3:h:dataprobe:iboot-pdu4a-n15:-
-
cpe:2.3:h:dataprobe:iboot-pdu4a-n20:-
-
cpe:2.3:h:dataprobe:iboot-pdu4sa-n15:-
-
cpe:2.3:h:dataprobe:iboot-pdu4sa-n20:-
-
cpe:2.3:h:dataprobe:iboot-pdu8a-2n15:-
-
cpe:2.3:h:dataprobe:iboot-pdu8a-2n20:-
-
cpe:2.3:h:dataprobe:iboot-pdu8a-n15:-
-
cpe:2.3:h:dataprobe:iboot-pdu8a-n20:-
-
cpe:2.3:h:dataprobe:iboot-pdu8sa-2n15:-
-
cpe:2.3:h:dataprobe:iboot-pdu8sa-n15:-
-
cpe:2.3:h:dataprobe:iboot-pdu8sa-n20:-
-
cpe:2.3:o:dataprobe:iboot-pdu4-n20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu4a-n15_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu4a-n20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu4sa-n15_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu4sa-n20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8a-2n15_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8a-2n20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8a-n15_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8a-n20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8sa-2n15_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8sa-n15_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8sa-n20_firmware:-