Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where...
Vulnerability Description
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specially crafted PHP script could use parameters from a HTTP request to create a URL capable of changing the host parameter. The changed host parameter in the HTTP could point to another host that will send a request to the host or IP specified in the changed host parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-3189
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Uri Katz
- Claroty Research
More from Dataprobe
View All →Affected Vendor
Dataprobe
View all reports →