Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerability.



Project Subscriptions

Vendors Products
Dataprobe Subscribe
Iboot-pdu4-n20 Subscribe
Iboot-pdu4-n20 Firmware Subscribe
Iboot-pdu4a-n15 Subscribe
Iboot-pdu4a-n15 Firmware Subscribe
Iboot-pdu4a-n20 Subscribe
Iboot-pdu4a-n20 Firmware Subscribe
Iboot-pdu4sa-n15 Subscribe
Iboot-pdu4sa-n15 Firmware Subscribe
Iboot-pdu4sa-n20 Subscribe
Iboot-pdu4sa-n20 Firmware Subscribe
Iboot-pdu8a-2n15 Subscribe
Iboot-pdu8a-2n15 Firmware Subscribe
Iboot-pdu8a-2n20 Subscribe
Iboot-pdu8a-2n20 Firmware Subscribe
Iboot-pdu8a-n15 Subscribe
Iboot-pdu8a-n15 Firmware Subscribe
Iboot-pdu8a-n20 Subscribe
Iboot-pdu8a-n20 Firmware Subscribe
Iboot-pdu8sa-2n15 Subscribe
Iboot-pdu8sa-2n15 Firmware Subscribe
Iboot-pdu8sa-n15 Subscribe
Iboot-pdu8sa-n15 Firmware Subscribe
Iboot-pdu8sa-n20 Subscribe
Iboot-pdu8sa-n20 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-42600 Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerability.
Fixes

Solution

Dataprobe has released the following version update to mitigate these vulnerabilities: * iBoot-PDU FW: Version 1.42.06162022 https://dataprobe.com/support-iboot-pdu/ Dataprobe also recommends users to disable the SNMP if it is not in use.


Workaround

No workaround given by the vendor.

History

Tue, 15 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-04-15T19:36:19.949Z

Reserved: 2022-09-12T20:20:12.777Z

Link: CVE-2022-3183

cve-icon Vulnrichment

Updated: 2024-08-03T01:00:10.493Z

cve-icon NVD

Status : Modified

Published: 2022-12-21T23:15:09.393

Modified: 2024-11-21T07:18:59.637

Link: CVE-2022-3183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses