MEDIUM · 6.5

CVE-2022-4945

The Dataprobe cloud usernames and passwords are stored in plain text in a specific file. Any user able to read this specific file from the device could compromise other devices connected to the user's...

Vulnerability Description

The Dataprobe cloud usernames and passwords are stored in plain text in a specific file. Any user able to read this specific file from the device could compromise other devices connected to the user's cloud.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
DataprobeIboot-Pdu4-N20 Firmware< 1.42.06162022
DataprobeIboot-Pdu4-N20-
DataprobeIboot-Pdu4Sa-N15 Firmware< 1.42.06162022
DataprobeIboot-Pdu4Sa-N15-
DataprobeIboot-Pdu4A-N15 Firmware< 1.42.06162022
DataprobeIboot-Pdu4A-N15-
DataprobeIboot-Pdu4Sa-N20 Firmware< 1.42.06162022
DataprobeIboot-Pdu4Sa-N20-
DataprobeIboot-Pdu4A-N20 Firmware< 1.42.06162022
DataprobeIboot-Pdu4A-N20-
DataprobeIboot-Pdu8Sa-N15 Firmware< 1.42.06162022
DataprobeIboot-Pdu8Sa-N15-
DataprobeIboot-Pdu8A-N15 Firmware< 1.42.06162022
DataprobeIboot-Pdu8A-N15-
DataprobeIboot-Pdu8Sa-2N15 Firmware< 1.42.06162022
DataprobeIboot-Pdu8Sa-2N15-
DataprobeIboot-Pdu8A-2N15 Firmware< 1.42.06162022
DataprobeIboot-Pdu8A-2N15-
DataprobeIboot-Pdu8Sa-N20 Firmware< 1.42.06162022
DataprobeIboot-Pdu8Sa-N20-

References

FAQ

What is CVE-2022-4945?

CVE-2022-4945 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Dataprobe cloud usernames and passwords are stored in plain text in a specific file. Any user able to read this specific file from the device could compromise other devices connected to the user's...

How severe is CVE-2022-4945?

CVE-2022-4945 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-4945?

Check the references section above for vendor advisories and patch information. Affected products include: Dataprobe Iboot-Pdu4-N20 Firmware, Dataprobe Iboot-Pdu4-N20, Dataprobe Iboot-Pdu4Sa-N15 Firmware, Dataprobe Iboot-Pdu4Sa-N15, Dataprobe Iboot-Pdu4A-N15 Firmware.