← Volver a CVEs
CVE-2023-3259
CRITICAL9.8
Descripcion
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By manipulating the IP address field in the "iBootPduSiteAuth" cookie, a malicious agent can direct the device to connect to a rouge database.Successful exploitation allows the malicious agent to take actions with administrator privileges including, but not limited to, manipulating power levels, modifying user accounts, and exporting confidential user information
Detalles CVE
Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado8/14/2023
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
dataprobe:iboot-pdu4-c20dataprobe:iboot-pdu4-c20_firmwaredataprobe:iboot-pdu4-n20dataprobe:iboot-pdu4-n20_firmwaredataprobe:iboot-pdu4a-c10dataprobe:iboot-pdu4a-c10_firmwaredataprobe:iboot-pdu4a-c20dataprobe:iboot-pdu4a-c20_firmwaredataprobe:iboot-pdu4a-n15dataprobe:iboot-pdu4a-n15_firmwaredataprobe:iboot-pdu4a-n20dataprobe:iboot-pdu4a-n20_firmwaredataprobe:iboot-pdu4sa-c10dataprobe:iboot-pdu4sa-c10_firmwaredataprobe:iboot-pdu4sa-c20dataprobe:iboot-pdu4sa-c20_firmwaredataprobe:iboot-pdu4sa-n15dataprobe:iboot-pdu4sa-n15_firmwaredataprobe:iboot-pdu4sa-n20dataprobe:iboot-pdu4sa-n20_firmwaredataprobe:iboot-pdu8a-2c10dataprobe:iboot-pdu8a-2c10_firmwaredataprobe:iboot-pdu8a-2c20dataprobe:iboot-pdu8a-2c20_firmwaredataprobe:iboot-pdu8a-2n15dataprobe:iboot-pdu8a-2n15_firmwaredataprobe:iboot-pdu8a-2n20dataprobe:iboot-pdu8a-2n20_firmwaredataprobe:iboot-pdu8a-c10dataprobe:iboot-pdu8a-c10_firmwaredataprobe:iboot-pdu8a-c20dataprobe:iboot-pdu8a-c20_firmwaredataprobe:iboot-pdu8a-n15dataprobe:iboot-pdu8a-n15_firmwaredataprobe:iboot-pdu8a-n20dataprobe:iboot-pdu8a-n20_firmwaredataprobe:iboot-pdu8sa-2n15dataprobe:iboot-pdu8sa-2n15_firmwaredataprobe:iboot-pdu8sa-c10dataprobe:iboot-pdu8sa-c10_firmwaredataprobe:iboot-pdu8sa-n15dataprobe:iboot-pdu8sa-n15_firmwaredataprobe:iboot-pdu8sa-n20dataprobe:iboot-pdu8sa-n20_firmware
Debilidades (CWE)
CWE-502CWE-502
Referencias
https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurking-in-data-centers.html(trellixpsirt@trellix.com)
https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurking-in-data-centers.html(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.