Vulnerability Details CVE-2022-3189
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specially crafted PHP script could use parameters from a HTTP request to create a URL capable of changing the host parameter. The changed host parameter in the HTTP could point to another host that will send a request to the host or IP specified in the changed host parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 18.6%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2022-3189
-
cpe:2.3:h:dataprobe:iboot-pdu4-n20:-
-
cpe:2.3:h:dataprobe:iboot-pdu4a-n15:-
-
cpe:2.3:h:dataprobe:iboot-pdu4a-n20:-
-
cpe:2.3:h:dataprobe:iboot-pdu4sa-n15:-
-
cpe:2.3:h:dataprobe:iboot-pdu4sa-n20:-
-
cpe:2.3:h:dataprobe:iboot-pdu8a-2n15:-
-
cpe:2.3:h:dataprobe:iboot-pdu8a-2n20:-
-
cpe:2.3:h:dataprobe:iboot-pdu8a-n15:-
-
cpe:2.3:h:dataprobe:iboot-pdu8a-n20:-
-
cpe:2.3:h:dataprobe:iboot-pdu8sa-2n15:-
-
cpe:2.3:h:dataprobe:iboot-pdu8sa-n15:-
-
cpe:2.3:h:dataprobe:iboot-pdu8sa-n20:-
-
cpe:2.3:o:dataprobe:iboot-pdu4-n20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu4a-n15_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu4a-n20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu4sa-n15_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu4sa-n20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8a-2n15_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8a-2n20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8a-n15_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8a-n20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8sa-2n15_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8sa-n15_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8sa-n20_firmware:-