Dataprobe

    Dashboard / Vendors

    Products: 47
    Vulnerabilities: 20
    Known Exploited: 0
    5
    Critical Level Threats
    7
    High Level Threats
    8
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-3264

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database. A malicious agent with the ability to execute operating system commands on the device can leverage this vulnerability to read, modify, or delete arbitrary database records.

    Last Modified: Nov 21, 2024
    Published: Aug 14, 2023

    CVE-2023-3263

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the mishandling of special characters when parsing credentials.Successful exploitation allows the malicious agent to obtain a valid authorization token and read information relating to the state of the relays and power distribution.

    Last Modified: Nov 21, 2024
    Published: Aug 14, 2023

    CVE-2023-3262

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database.A malicious agent with the ability to execute operating system commands on the device can leverage this vulnerability to read, modify, or delete arbitrary database records.

    Last Modified: Nov 21, 2024
    Published: Aug 14, 2023

    CVE-2023-3261

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Successful exploitation could cause denial of service or unexpected behavior with respect to all interactions relying on the targeted vulnerable binary, including the ability to log in via the web server.

    Last Modified: Nov 21, 2024
    Published: Aug 14, 2023

    CVE-2023-3260

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute arbitrary command on the underlying Linux operating system.

    Last Modified: Nov 21, 2024
    Published: Aug 14, 2023
    Items Per Page
    Dataprobe Vulnerabilities & Security CVEs | CVE-DB