← All CVEs

CVE-2022-3184

critical · 9.8

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to access an old PHP page vulnerable to directory traversal, which may allow a user to write a file to the webroot directory.

9.8
CVSS
11.6%
EPSS (exploit prob.)
96th
EPSS percentile
2022-12-21
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
dataprobeiboot-pdu4-n20_firmware< 1.42.06162022
dataprobeiboot-pdu4-n20all versions
dataprobeiboot-pdu4sa-n15_firmware< 1.42.06162022
dataprobeiboot-pdu4sa-n15all versions
dataprobeiboot-pdu4a-n15_firmware< 1.42.06162022
dataprobeiboot-pdu4a-n15all versions
dataprobeiboot-pdu4sa-n20_firmware< 1.42.06162022
dataprobeiboot-pdu4sa-n20all versions
dataprobeiboot-pdu4a-n20_firmware< 1.42.06162022
dataprobeiboot-pdu4a-n20all versions
dataprobeiboot-pdu8sa-n15_firmware< 1.42.06162022
dataprobeiboot-pdu8sa-n15all versions
dataprobeiboot-pdu8a-n15_firmware< 1.42.06162022
dataprobeiboot-pdu8a-n15all versions
dataprobeiboot-pdu8sa-2n15_firmware< 1.42.06162022
dataprobeiboot-pdu8sa-2n15all versions
dataprobeiboot-pdu8a-2n15_firmware< 1.42.06162022
dataprobeiboot-pdu8a-2n15all versions
dataprobeiboot-pdu8sa-n20_firmware< 1.42.06162022
dataprobeiboot-pdu8sa-n20all versions
dataprobeiboot-pdu8a-n20_firmware< 1.42.06162022
dataprobeiboot-pdu8a-n20all versions
dataprobeiboot-pdu8a-2n20_firmware< 1.42.06162022
dataprobeiboot-pdu8a-2n20all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-3184