CVE-2022-47311

A proprietary protocol for iBoot devices is used for control and keepalive commands. The function compares the username and password; it also contains the configuration data for the user specified. If the user does not exist, then it sends a value for username and password, which allows successful authentication for a connection.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.5 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
icscertCNA
8.5 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 24%
VendorProductVersion
dataprobeiboot-pdu4-n20_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu4sa-n15_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu4a-n15_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu4sa-n20_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu4a-n20_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8sa-n15_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8a-n15_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8sa-2n15_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8a-2n15_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8sa-n20_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8a-n20_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8a-2n20_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu4-c20_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu4a-c10_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu4sa-c10_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8a-c10_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8sa-c10_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8a-2c20_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu4sa-c20_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu4a-c20_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8a-2c10_firmware
𝑥
< 1.42.06162022
dataprobeiboot-pdu8a-c20_firmware
𝑥
< 1.42.06162022
𝑥
= Vulnerable software versions