Lucene search

K
cvelistIcscertCVELIST:CVE-2022-3188
HistoryDec 21, 2022 - 10:30 p.m.

CVE-2022-3188

2022-12-2122:30:19
CWE-863
icscert
www.cve.org
dataprobe
iboot-pdu
firmware
vulnerability
unauthenticated users
php index pages
history file
specific users.

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

32.1%

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerabilityΒ where unauthenticated users could open PHP index pages without authentication and download the history file from the device; the history file includes the latest actions completed by specific users.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "iBoot-PDU FW",
    "vendor": "Dataprobe",
    "versions": [
      {
        "lessThanOrEqual": "1.42.06162022",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

32.1%

Related for CVELIST:CVE-2022-3188