Link | Resource |
---|---|
https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurking-in-data-centers.html | Vendor Advisory |
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
Configuration 14 (hide)
AND |
|
Configuration 15 (hide)
AND |
|
Configuration 16 (hide)
AND |
|
Configuration 17 (hide)
AND |
|
Configuration 18 (hide)
AND |
|
Configuration 19 (hide)
AND |
|
Configuration 20 (hide)
AND |
|
Configuration 21 (hide)
AND |
|
Configuration 22 (hide)
AND |
|
Configuration 23 (hide)
AND |
|
25 Aug 2023, 05:15
Type | Values Removed | Values Added |
---|---|---|
Summary | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute arbitrary command on the underlying Linux operating system. |
22 Aug 2023, 16:36
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurking-in-data-centers.html - Vendor Advisory | |
CPE | cpe:2.3:o:dataprobe:iboot-pdu4a-n15_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu8sa-n15_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu4a-c20_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu8a-n15_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu8a-2n15_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu4sa-n15_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu4sa-n15:-:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu8a-2c10_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu8a-2c20:-:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu4sa-n20:-:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu8a-2n20_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu8sa-n15:-:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu4a-n20_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu8sa-2n15:-:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu4-n20:-:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu8sa-c10_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu8sa-n20:-:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu4-n20_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu4a-c20:-:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu4a-n20:-:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu8a-n15:-:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu4sa-c10_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu4sa-n20_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu4sa-c20_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu8sa-2n15_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu4a-c10:-:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu8a-n20:-:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu8a-2c10:-:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu4sa-c10:-:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu8a-2c20_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu4a-n15:-:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu4a-c10_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu4sa-c20:-:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu8sa-n20_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu8a-c20:-:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu8a-c10:-:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu8a-2n15:-:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu8a-c20_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu4-c20:-:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu8a-n20_firmware:*:*:*:*:*:*:*:* cpe:2.3:a:cyberpower:powerpanel_server:*:*:*:*:enterprise:*:*:* cpe:2.3:h:dataprobe:iboot-pdu8a-2n20:-:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu4-c20_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dataprobe:iboot-pdu8sa-c10:-:*:*:*:*:*:*:* cpe:2.3:o:dataprobe:iboot-pdu8a-c10_firmware:*:*:*:*:*:*:*:* |
|
First Time |
Dataprobe iboot-pdu8a-n15 Firmware
Dataprobe iboot-pdu8a-2n20 Firmware Cyberpower powerpanel Server Dataprobe iboot-pdu4sa-n20 Dataprobe iboot-pdu8a-2c20 Firmware Dataprobe iboot-pdu4sa-c10 Firmware Dataprobe iboot-pdu4a-c10 Dataprobe iboot-pdu8a-2c10 Firmware Dataprobe iboot-pdu4sa-n20 Firmware Dataprobe iboot-pdu4sa-c10 Dataprobe iboot-pdu8a-2n20 Dataprobe iboot-pdu8a-n20 Dataprobe iboot-pdu4sa-c20 Dataprobe iboot-pdu4a-n15 Firmware Dataprobe iboot-pdu8a-n20 Firmware Dataprobe iboot-pdu8sa-n20 Dataprobe iboot-pdu8sa-2n15 Firmware Dataprobe iboot-pdu8sa-n15 Firmware Dataprobe iboot-pdu4sa-c20 Firmware Dataprobe iboot-pdu4a-c20 Firmware Dataprobe iboot-pdu4sa-n15 Dataprobe Dataprobe iboot-pdu8a-2c20 Dataprobe iboot-pdu8sa-c10 Firmware Dataprobe iboot-pdu8a-c10 Dataprobe iboot-pdu8sa-2n15 Cyberpower Dataprobe iboot-pdu8sa-n15 Dataprobe iboot-pdu8a-c10 Firmware Dataprobe iboot-pdu8sa-c10 Dataprobe iboot-pdu8a-2n15 Dataprobe iboot-pdu8sa-n20 Firmware Dataprobe iboot-pdu4a-n20 Dataprobe iboot-pdu8a-c20 Firmware Dataprobe iboot-pdu8a-c20 Dataprobe iboot-pdu8a-2n15 Firmware Dataprobe iboot-pdu8a-2c10 Dataprobe iboot-pdu4a-n15 Dataprobe iboot-pdu4-c20 Dataprobe iboot-pdu4a-n20 Firmware Dataprobe iboot-pdu4-n20 Dataprobe iboot-pdu4sa-n15 Firmware Dataprobe iboot-pdu4a-c20 Dataprobe iboot-pdu4-c20 Firmware Dataprobe iboot-pdu8a-n15 Dataprobe iboot-pdu4-n20 Firmware Dataprobe iboot-pdu4a-c10 Firmware |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
CWE | CWE-78 |
14 Aug 2023, 05:15
Type | Values Removed | Values Added |
---|---|---|
Summary | When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without sanitization into CMD running as NT/Authority System. An authenticated attacker can leverage this vulnerability to execute arbitrary code with system-level access to the CyberPower PowerPanel Enterprise server. |
14 Aug 2023, 04:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Published : 2023-08-14 04:15
Updated : 2024-02-28 20:33
NVD link : CVE-2023-3260
Mitre link : CVE-2023-3260
CVE.ORG link : CVE-2023-3260
JSON object : View
dataprobe
- iboot-pdu4a-c20
- iboot-pdu8a-n15_firmware
- iboot-pdu8sa-2n15_firmware
- iboot-pdu8sa-c10_firmware
- iboot-pdu4-n20
- iboot-pdu4a-n20
- iboot-pdu8sa-n20
- iboot-pdu8a-2n15
- iboot-pdu8a-n15
- iboot-pdu4-c20
- iboot-pdu4sa-c20_firmware
- iboot-pdu4sa-c20
- iboot-pdu4sa-n20
- iboot-pdu4a-c10
- iboot-pdu8a-2n20_firmware
- iboot-pdu4sa-n15_firmware
- iboot-pdu8a-2c10_firmware
- iboot-pdu8a-2c20
- iboot-pdu4-n20_firmware
- iboot-pdu8a-2c20_firmware
- iboot-pdu8sa-2n15
- iboot-pdu4sa-n20_firmware
- iboot-pdu8a-n20
- iboot-pdu4-c20_firmware
- iboot-pdu8a-n20_firmware
- iboot-pdu8a-c10_firmware
- iboot-pdu8a-c20
- iboot-pdu8sa-n15
- iboot-pdu4sa-c10_firmware
- iboot-pdu8a-2n15_firmware
- iboot-pdu4a-n20_firmware
- iboot-pdu4a-n15
- iboot-pdu8sa-n20_firmware
- iboot-pdu8a-2n20
- iboot-pdu8a-c20_firmware
- iboot-pdu8a-2c10
- iboot-pdu4a-c10_firmware
- iboot-pdu4a-c20_firmware
- iboot-pdu8sa-n15_firmware
- iboot-pdu4sa-n15
- iboot-pdu8a-c10
- iboot-pdu4a-n15_firmware
- iboot-pdu4sa-c10
- iboot-pdu8sa-c10
cyberpower
- powerpanel_server
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')