← Zuruck zu CVEs
CVE-2023-3259
CRITICAL9.8
Beschreibung
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By manipulating the IP address field in the "iBootPduSiteAuth" cookie, a malicious agent can direct the device to connect to a rouge database.Successful exploitation allows the malicious agent to take actions with administrator privileges including, but not limited to, manipulating power levels, modifying user accounts, and exporting confidential user information
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht8/14/2023
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
dataprobe:iboot-pdu4-c20dataprobe:iboot-pdu4-c20_firmwaredataprobe:iboot-pdu4-n20dataprobe:iboot-pdu4-n20_firmwaredataprobe:iboot-pdu4a-c10dataprobe:iboot-pdu4a-c10_firmwaredataprobe:iboot-pdu4a-c20dataprobe:iboot-pdu4a-c20_firmwaredataprobe:iboot-pdu4a-n15dataprobe:iboot-pdu4a-n15_firmwaredataprobe:iboot-pdu4a-n20dataprobe:iboot-pdu4a-n20_firmwaredataprobe:iboot-pdu4sa-c10dataprobe:iboot-pdu4sa-c10_firmwaredataprobe:iboot-pdu4sa-c20dataprobe:iboot-pdu4sa-c20_firmwaredataprobe:iboot-pdu4sa-n15dataprobe:iboot-pdu4sa-n15_firmwaredataprobe:iboot-pdu4sa-n20dataprobe:iboot-pdu4sa-n20_firmwaredataprobe:iboot-pdu8a-2c10dataprobe:iboot-pdu8a-2c10_firmwaredataprobe:iboot-pdu8a-2c20dataprobe:iboot-pdu8a-2c20_firmwaredataprobe:iboot-pdu8a-2n15dataprobe:iboot-pdu8a-2n15_firmwaredataprobe:iboot-pdu8a-2n20dataprobe:iboot-pdu8a-2n20_firmwaredataprobe:iboot-pdu8a-c10dataprobe:iboot-pdu8a-c10_firmwaredataprobe:iboot-pdu8a-c20dataprobe:iboot-pdu8a-c20_firmwaredataprobe:iboot-pdu8a-n15dataprobe:iboot-pdu8a-n15_firmwaredataprobe:iboot-pdu8a-n20dataprobe:iboot-pdu8a-n20_firmwaredataprobe:iboot-pdu8sa-2n15dataprobe:iboot-pdu8sa-2n15_firmwaredataprobe:iboot-pdu8sa-c10dataprobe:iboot-pdu8sa-c10_firmwaredataprobe:iboot-pdu8sa-n15dataprobe:iboot-pdu8sa-n15_firmwaredataprobe:iboot-pdu8sa-n20dataprobe:iboot-pdu8sa-n20_firmware
Schwachen (CWE)
CWE-502CWE-502
Referenzen
https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurking-in-data-centers.html(trellixpsirt@trellix.com)
https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurking-in-data-centers.html(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.