Lucene search

K
cve[email protected]CVE-2022-47311
HistoryMay 22, 2023 - 11:15 p.m.

CVE-2022-47311

2023-05-2223:15:09
web.nvd.nist.gov
18
cve-2022-47311
iboot devices
authentication bypass
proprietary protocol
nvd

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.5%

A proprietary protocol for iBoot devices is used for control and keepalive commands. The function compares the username and password; it also contains the configuration data for the user specified. If the user does not exist, then it sends a value for username and password, which allows successful authentication for a connection.

Affected configurations

NVD
Node
dataprobeiboot-pdu4-n20_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu4-n20Match-
Node
dataprobeiboot-pdu4sa-n15_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu4sa-n15Match-
Node
dataprobeiboot-pdu4a-n15_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu4a-n15Match-
Node
dataprobeiboot-pdu4sa-n20_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu4sa-n20Match-
Node
dataprobeiboot-pdu4a-n20_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu4a-n20Match-
Node
dataprobeiboot-pdu8sa-n15_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu8sa-n15Match-
Node
dataprobeiboot-pdu8a-n15_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu8a-n15Match-
Node
dataprobeiboot-pdu8sa-2n15_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu8sa-2n15Match-
Node
dataprobeiboot-pdu8a-2n15_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu8a-2n15Match-
Node
dataprobeiboot-pdu8sa-n20_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu8sa-n20Match-
Node
dataprobeiboot-pdu8a-n20_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu8a-n20Match-
Node
dataprobeiboot-pdu8a-2n20_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu8a-2n20Match-
Node
dataprobeiboot-pdu4-c20_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu4-c20Match-
Node
dataprobeiboot-pdu4a-c10_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu4a-c10Match-
Node
dataprobeiboot-pdu4sa-c10_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu4sa-c10Match-
Node
dataprobeiboot-pdu8a-c10_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu8a-c10Match-
Node
dataprobeiboot-pdu8sa-c10_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu8sa-c10Match-
Node
dataprobeiboot-pdu8a-2c20_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu8a-2c20Match-
Node
dataprobeiboot-pdu4sa-c20_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu4sa-c20Match-
Node
dataprobeiboot-pdu4a-c20_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu4a-c20Match-
Node
dataprobeiboot-pdu8a-2c10_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu8a-2c10Match-
Node
dataprobeiboot-pdu8a-c20_firmwareRange<1.42.06162022
AND
dataprobeiboot-pdu8a-c20Match-

CNA Affected

[
  {
    "vendor": "Dataprobe, Inc.",
    "product": "Dataprobe iBoot-PDU FW",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "1.42.06162022",
        "versionType": "custom"
      }
    ]
  }
]

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.5%

Related for CVE-2022-47311