HIGH · 7.2

CVE-2023-3260

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulner...

Vulnerability Description

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute arbitrary command on the underlying Linux operating system.

CVSS Score

7.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CyberpowerPowerpanel Server< 2.6.9
DataprobeIboot-Pdu4A-C10 Firmware< 1.44.0804202
DataprobeIboot-Pdu4A-C10-
DataprobeIboot-Pdu4A-C20 Firmware< 1.44.0804202
DataprobeIboot-Pdu4A-C20-
DataprobeIboot-Pdu4A-N15 Firmware< 1.44.0804202
DataprobeIboot-Pdu4A-N15-
DataprobeIboot-Pdu4A-N20 Firmware< 1.44.0804202
DataprobeIboot-Pdu4A-N20-
DataprobeIboot-Pdu4-C20 Firmware< 1.44.0804202
DataprobeIboot-Pdu4-C20-
DataprobeIboot-Pdu4-N20 Firmware< 1.44.0804202
DataprobeIboot-Pdu4-N20-
DataprobeIboot-Pdu4Sa-C10 Firmware< 1.44.0804202
DataprobeIboot-Pdu4Sa-C10-
DataprobeIboot-Pdu4Sa-C20 Firmware< 1.44.0804202
DataprobeIboot-Pdu4Sa-C20-
DataprobeIboot-Pdu4Sa-N15 Firmware< 1.44.0804202
DataprobeIboot-Pdu4Sa-N15-
DataprobeIboot-Pdu4Sa-N20 Firmware< 1.44.0804202

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-3260?

CVE-2023-3260 is a vulnerability with a CVSS score of 7.2 (HIGH). The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulner...

How severe is CVE-2023-3260?

CVE-2023-3260 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-3260?

Check the references section above for vendor advisories and patch information. Affected products include: Cyberpower Powerpanel Server, Dataprobe Iboot-Pdu4A-C10 Firmware, Dataprobe Iboot-Pdu4A-C10, Dataprobe Iboot-Pdu4A-C20 Firmware, Dataprobe Iboot-Pdu4A-C20.