Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where...
Vulnerability Description
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is established with the database. However, these PHP pages do not verify the validity of a user. Attackers could leverage this lack of verification to read the state of outlets.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-3187
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Uri Katz
- Claroty Research
More from Dataprobe
View All →Affected Vendor
Dataprobe
View all reports →