Vulnerability Details CVE-2023-3260
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute arbitrary command on the underlying Linux operating system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.1%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2023-3260
-
cpe:2.3:a:cyberpower:powerpanel_server:*
-
cpe:2.3:h:dataprobe:iboot-pdu4-c20:-
-
cpe:2.3:h:dataprobe:iboot-pdu4-n20:-
-
cpe:2.3:h:dataprobe:iboot-pdu4a-c10:-
-
cpe:2.3:h:dataprobe:iboot-pdu4a-c20:-
-
cpe:2.3:h:dataprobe:iboot-pdu4a-n15:-
-
cpe:2.3:h:dataprobe:iboot-pdu4a-n20:-
-
cpe:2.3:h:dataprobe:iboot-pdu4sa-c10:-
-
cpe:2.3:h:dataprobe:iboot-pdu4sa-c20:-
-
cpe:2.3:h:dataprobe:iboot-pdu4sa-n15:-
-
cpe:2.3:h:dataprobe:iboot-pdu4sa-n20:-
-
cpe:2.3:h:dataprobe:iboot-pdu8a-2c10:-
-
cpe:2.3:h:dataprobe:iboot-pdu8a-2c20:-
-
cpe:2.3:h:dataprobe:iboot-pdu8a-2n15:-
-
cpe:2.3:h:dataprobe:iboot-pdu8a-2n20:-
-
cpe:2.3:h:dataprobe:iboot-pdu8a-c10:-
-
cpe:2.3:h:dataprobe:iboot-pdu8a-c20:-
-
cpe:2.3:h:dataprobe:iboot-pdu8a-n15:-
-
cpe:2.3:h:dataprobe:iboot-pdu8a-n20:-
-
cpe:2.3:h:dataprobe:iboot-pdu8sa-2n15:-
-
cpe:2.3:h:dataprobe:iboot-pdu8sa-c10:-
-
cpe:2.3:h:dataprobe:iboot-pdu8sa-n15:-
-
cpe:2.3:h:dataprobe:iboot-pdu8sa-n20:-
-
cpe:2.3:o:dataprobe:iboot-pdu4-c20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu4-c20_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu4-n20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu4-n20_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu4a-c10_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu4a-c10_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu4a-c20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu4a-c20_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu4a-n15_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu4a-n15_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu4a-n20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu4a-n20_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu4sa-c10_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu4sa-c10_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu4sa-c20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu4sa-c20_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu4sa-n15_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu4sa-n15_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu4sa-n20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu4sa-n20_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu8a-2c10_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8a-2c10_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu8a-2c20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8a-2c20_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu8a-2n15_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8a-2n15_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu8a-2n20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8a-2n20_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu8a-c10_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8a-c10_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu8a-c20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8a-c20_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu8a-n15_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8a-n15_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu8a-n20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8a-n20_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu8sa-2n15_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8sa-2n15_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu8sa-c10_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8sa-c10_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu8sa-n15_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8sa-n15_firmware:1.42.06162022
-
cpe:2.3:o:dataprobe:iboot-pdu8sa-n20_firmware:-
-
cpe:2.3:o:dataprobe:iboot-pdu8sa-n20_firmware:1.42.06162022