Remote Access Vulnerability in Dataprobe iBoot-PDU Firmware Versions Prior to 1.42.06162022

Remote Access Vulnerability in Dataprobe iBoot-PDU Firmware Versions Prior to 1.42.06162022

CVE-2022-3186 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the device’s main management page from the cloud. This feature enables users to remotely connect devices, however, the current implementation permits users to access other device's information.

Learn more about our Cloud Audit.