CVE-2022-3183

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerability. 



OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
dataprobeiboot-pdu4-n20_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu4sa-n15_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu4a-n15_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu4sa-n20_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu4a-n20_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8sa-n15_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8a-n15_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8sa-2n15_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8a-2n15_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8sa-n20_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8a-n20_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8a-2n20_firmware
𝑥
< 1.42.06162022
𝑥
= Vulnerable software versions