CVE-2023-3260

EUVD-2023-43936
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute arbitrary command on the underlying Linux operating system.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
trellixCNA
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
Affected Products (NVD)
VendorProductVersion
cyberpowerpowerpanel_server
𝑥
< 2.6.9
dataprobeiboot-pdu4a-c10_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu4a-c20_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu4a-n15_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu4a-n20_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu4-c20_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu4-n20_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu4sa-c10_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu4sa-c20_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu4sa-n15_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu4sa-n20_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8a-2c10_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8a-2c20_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8a-2n15_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8a-2n20_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8a-c10_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8a-c20_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8a-n15_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8a-n20_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8sa-2n15_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8sa-c10_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8sa-n15_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8sa-n20_firmware
𝑥
< 1.44.0804202
𝑥
= Vulnerable software versions