MEDIUM · 5.3

CVE-2022-3187

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is established with the database. However, these PHP pages ...

Vulnerability Description

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is established with the database. However, these PHP pages do not verify the validity of a user. Attackers could leverage this lack of verification to read the state of outlets.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
DataprobeIboot-Pdu4-N20 Firmware< 1.42.06162022
DataprobeIboot-Pdu4-N20-
DataprobeIboot-Pdu4Sa-N15 Firmware< 1.42.06162022
DataprobeIboot-Pdu4Sa-N15-
DataprobeIboot-Pdu4A-N15 Firmware< 1.42.06162022
DataprobeIboot-Pdu4A-N15-
DataprobeIboot-Pdu4Sa-N20 Firmware< 1.42.06162022
DataprobeIboot-Pdu4Sa-N20-
DataprobeIboot-Pdu4A-N20 Firmware< 1.42.06162022
DataprobeIboot-Pdu4A-N20-
DataprobeIboot-Pdu8Sa-N15 Firmware< 1.42.06162022
DataprobeIboot-Pdu8Sa-N15-
DataprobeIboot-Pdu8A-N15 Firmware< 1.42.06162022
DataprobeIboot-Pdu8A-N15-
DataprobeIboot-Pdu8Sa-2N15 Firmware< 1.42.06162022
DataprobeIboot-Pdu8Sa-2N15-
DataprobeIboot-Pdu8A-2N15 Firmware< 1.42.06162022
DataprobeIboot-Pdu8A-2N15-
DataprobeIboot-Pdu8Sa-N20 Firmware< 1.42.06162022
DataprobeIboot-Pdu8Sa-N20-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-3187?

CVE-2022-3187 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is established with the database. However, these PHP pages ...

How severe is CVE-2022-3187?

CVE-2022-3187 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-3187?

Check the references section above for vendor advisories and patch information. Affected products include: Dataprobe Iboot-Pdu4-N20 Firmware, Dataprobe Iboot-Pdu4-N20, Dataprobe Iboot-Pdu4Sa-N15 Firmware, Dataprobe Iboot-Pdu4Sa-N15, Dataprobe Iboot-Pdu4A-N15 Firmware.