Vulnerability Description
A proprietary protocol for iBoot devices is used for control and keepalive commands. The function compares the username and password; it also contains the configuration data for the user specified. If the user does not exist, then it sends a value for username and password, which allows successful authentication for a connection.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dataprobe | Iboot-Pdu4-N20 Firmware | < 1.42.06162022 |
| Dataprobe | Iboot-Pdu4-N20 | - |
| Dataprobe | Iboot-Pdu4Sa-N15 Firmware | < 1.42.06162022 |
| Dataprobe | Iboot-Pdu4Sa-N15 | - |
| Dataprobe | Iboot-Pdu4A-N15 Firmware | < 1.42.06162022 |
| Dataprobe | Iboot-Pdu4A-N15 | - |
| Dataprobe | Iboot-Pdu4Sa-N20 Firmware | < 1.42.06162022 |
| Dataprobe | Iboot-Pdu4Sa-N20 | - |
| Dataprobe | Iboot-Pdu4A-N20 Firmware | < 1.42.06162022 |
| Dataprobe | Iboot-Pdu4A-N20 | - |
| Dataprobe | Iboot-Pdu8Sa-N15 Firmware | < 1.42.06162022 |
| Dataprobe | Iboot-Pdu8Sa-N15 | - |
| Dataprobe | Iboot-Pdu8A-N15 Firmware | < 1.42.06162022 |
| Dataprobe | Iboot-Pdu8A-N15 | - |
| Dataprobe | Iboot-Pdu8Sa-2N15 Firmware | < 1.42.06162022 |
| Dataprobe | Iboot-Pdu8Sa-2N15 | - |
| Dataprobe | Iboot-Pdu8A-2N15 Firmware | < 1.42.06162022 |
| Dataprobe | Iboot-Pdu8A-2N15 | - |
| Dataprobe | Iboot-Pdu8Sa-N20 Firmware | < 1.42.06162022 |
| Dataprobe | Iboot-Pdu8Sa-N20 | - |
References
- https://dataprobe.com/support/iboot-pdu/local_upgrade_pdu_procedure.pdfProduct
- https://www.cisa.gov/news-events/ics-advisories/icsa-22-263-03PatchThird Party AdvisoryUS Government Resource
- https://dataprobe.com/support/iboot-pdu/local_upgrade_pdu_procedure.pdfProduct
- https://www.cisa.gov/news-events/ics-advisories/icsa-22-263-03PatchThird Party AdvisoryUS Government Resource
FAQ
What is CVE-2022-47311?
CVE-2022-47311 is a vulnerability with a CVSS score of 8.5 (HIGH). A proprietary protocol for iBoot devices is used for control and keepalive commands. The function compares the username and password; it also contains the configuration data for the user specified. If...
How severe is CVE-2022-47311?
CVE-2022-47311 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-47311?
Check the references section above for vendor advisories and patch information. Affected products include: Dataprobe Iboot-Pdu4-N20 Firmware, Dataprobe Iboot-Pdu4-N20, Dataprobe Iboot-Pdu4Sa-N15 Firmware, Dataprobe Iboot-Pdu4Sa-N15, Dataprobe Iboot-Pdu4A-N15 Firmware.