CRITICAL · 9.8

CVE-2023-3259

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By manipulating the IP address field in the "iBootPduSiteAuth" cookie, a malicious age...

Vulnerability Description

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By manipulating the IP address field in the "iBootPduSiteAuth" cookie, a malicious agent can direct the device to connect to a rouge database.Successful exploitation allows the malicious agent to take actions with administrator privileges including, but not limited to, manipulating power levels, modifying user accounts, and exporting confidential user information

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DataprobeIboot-Pdu4A-C10 Firmware< 1.44.0804202
DataprobeIboot-Pdu4A-C10-
DataprobeIboot-Pdu4A-C20 Firmware< 1.44.0804202
DataprobeIboot-Pdu4A-C20-
DataprobeIboot-Pdu4A-N15 Firmware< 1.44.0804202
DataprobeIboot-Pdu4A-N15-
DataprobeIboot-Pdu4A-N20 Firmware< 1.44.0804202
DataprobeIboot-Pdu4A-N20-
DataprobeIboot-Pdu4-C20 Firmware< 1.44.0804202
DataprobeIboot-Pdu4-C20-
DataprobeIboot-Pdu4-N20 Firmware< 1.44.0804202
DataprobeIboot-Pdu4-N20-
DataprobeIboot-Pdu4Sa-C10 Firmware< 1.44.0804202
DataprobeIboot-Pdu4Sa-C10-
DataprobeIboot-Pdu4Sa-C20 Firmware< 1.44.0804202
DataprobeIboot-Pdu4Sa-C20-
DataprobeIboot-Pdu4Sa-N15 Firmware< 1.44.0804202
DataprobeIboot-Pdu4Sa-N15-
DataprobeIboot-Pdu4Sa-N20 Firmware< 1.44.0804202
DataprobeIboot-Pdu4Sa-N20-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-3259?

CVE-2023-3259 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By manipulating the IP address field in the "iBootPduSiteAuth" cookie, a malicious age...

How severe is CVE-2023-3259?

CVE-2023-3259 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2023-3259?

Check the references section above for vendor advisories and patch information. Affected products include: Dataprobe Iboot-Pdu4A-C10 Firmware, Dataprobe Iboot-Pdu4A-C10, Dataprobe Iboot-Pdu4A-C20 Firmware, Dataprobe Iboot-Pdu4A-C20, Dataprobe Iboot-Pdu4A-N15 Firmware.