CVE-2023-3260

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute arbitrary command on the underlying Linux operating system.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
trellixCNA
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
VendorProductVersion
cyberpowerpowerpanel_server
𝑥
< 2.6.9
dataprobeiboot-pdu4a-c10_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu4a-c20_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu4a-n15_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu4a-n20_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu4-c20_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu4-n20_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu4sa-c10_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu4sa-c20_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu4sa-n15_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu4sa-n20_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8a-2c10_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8a-2c20_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8a-2n15_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8a-2n20_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8a-c10_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8a-c20_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8a-n15_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8a-n20_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8sa-2n15_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8sa-c10_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8sa-n15_firmware
𝑥
< 1.44.0804202
dataprobeiboot-pdu8sa-n20_firmware
𝑥
< 1.44.0804202
𝑥
= Vulnerable software versions