Vulnerability Description
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the mishandling of special characters when parsing credentials.Successful exploitation allows the malicious agent to obtain a valid authorization token and read information relating to the state of the relays and power distribution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dataprobe | Iboot-Pdu4A-C10 Firmware | < 1.44.0804202 |
| Dataprobe | Iboot-Pdu4A-C10 | - |
| Dataprobe | Iboot-Pdu4A-C20 Firmware | < 1.44.0804202 |
| Dataprobe | Iboot-Pdu4A-C20 | - |
| Dataprobe | Iboot-Pdu4A-N15 Firmware | < 1.44.0804202 |
| Dataprobe | Iboot-Pdu4A-N15 | - |
| Dataprobe | Iboot-Pdu4A-N20 Firmware | < 1.44.0804202 |
| Dataprobe | Iboot-Pdu4A-N20 | - |
| Dataprobe | Iboot-Pdu4-C20 Firmware | < 1.44.0804202 |
| Dataprobe | Iboot-Pdu4-C20 | - |
| Dataprobe | Iboot-Pdu4-N20 Firmware | < 1.44.0804202 |
| Dataprobe | Iboot-Pdu4-N20 | - |
| Dataprobe | Iboot-Pdu4Sa-C10 Firmware | < 1.44.0804202 |
| Dataprobe | Iboot-Pdu4Sa-C10 | - |
| Dataprobe | Iboot-Pdu4Sa-C20 Firmware | < 1.44.0804202 |
| Dataprobe | Iboot-Pdu4Sa-C20 | - |
| Dataprobe | Iboot-Pdu4Sa-N15 Firmware | < 1.44.0804202 |
| Dataprobe | Iboot-Pdu4Sa-N15 | - |
| Dataprobe | Iboot-Pdu4Sa-N20 Firmware | < 1.44.0804202 |
| Dataprobe | Iboot-Pdu4Sa-N20 | - |
Related Weaknesses (CWE)
References
- https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurkingVendor Advisory
- https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurkingVendor Advisory
FAQ
What is CVE-2023-3263?
CVE-2023-3263 is a vulnerability with a CVSS score of 7.5 (HIGH). The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the mishandling of special characters when parsing credentials.S...
How severe is CVE-2023-3263?
CVE-2023-3263 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-3263?
Check the references section above for vendor advisories and patch information. Affected products include: Dataprobe Iboot-Pdu4A-C10 Firmware, Dataprobe Iboot-Pdu4A-C10, Dataprobe Iboot-Pdu4A-C20 Firmware, Dataprobe Iboot-Pdu4A-C20, Dataprobe Iboot-Pdu4A-N15 Firmware.