CVE-2022-3183

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerabilitywhere a specificfunction does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerability. 



OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
icscertCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
dataprobeiboot-pdu4-n20_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu4sa-n15_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu4a-n15_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu4sa-n20_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu4a-n20_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8sa-n15_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8a-n15_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8sa-2n15_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8a-2n15_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8sa-n20_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8a-n20_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8a-2n20_firmware
𝑥
< 1.42.06162022
𝑥
= Vulnerable software versions