Lucene search

K
cvelistIcscertCVELIST:CVE-2022-47311
HistoryMay 22, 2023 - 10:12 p.m.

CVE-2022-47311 CVE-2022-47311

2023-05-2222:12:51
icscert
www.cve.org
proprietary protocol
iboot devices
control commands
keepalive
authentication

8.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

9.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.5%

A proprietary protocol for iBoot devices is used for control and keepalive commands. The function compares the username and password; it also contains the configuration data for the user specified. If the user does not exist, then it sends a value for username and password, which allows successful authentication for a connection.

CNA Affected

[
  {
    "vendor": "Dataprobe, Inc.",
    "product": "Dataprobe iBoot-PDU FW",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "1.42.06162022",
        "versionType": "custom"
      }
    ]
  }
]

8.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

9.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.5%

Related for CVELIST:CVE-2022-47311