Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Iboot Pdu4a C10 Firmware HIGH 7.5
CVE-2023-3263

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the mishandli…

Fix: 1.44.0804202+
Fix from $1,950 2023-08-14
Iboot Pdu4a C10 Firmware MEDIUM 6.7
CVE-2023-3262

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres…

Fix: 1.44.0804202+
Fix from $1,600 2023-08-14
Iboot Pdu4a C10 Firmware CRITICAL 9.8
CVE-2023-3259

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By manipulating the IP address fiel…

Fix: 1.44.0804202+
Fix from $2,300 2023-08-14
Iboot Pdu4 N20 Firmware CRITICAL 9.8
CVE-2022-46658

The affected product is vulnerable to a stack-based buffer overflow which could lead to a denial of service or remote code execution.

Fix: 1.42.06162022+
Fix from $2,300 2023-05-22
Iboot Pdu4 N20 Firmware CRITICAL 9.8
CVE-2022-46738

The affected product exposes multiple sensitive data fields of the affected product. An attacker can use the SNMP command to get device mac address a…

Fix: 1.42.06162022+
Fix from $2,300 2023-05-22
Iboot Pdu4 N20 Firmware HIGH 8.8
CVE-2022-47311

A proprietary protocol for iBoot devices is used for control and keepalive commands. The function compares the username and password; it also contain…

Fix: 1.42.06162022+
Fix from $1,950 2023-05-22
Iboot Pdu4 N20 Firmware HIGH 8.1
CVE-2022-47320

The iBoot device’s basic discovery protocol assists in initial device configuration. The discovery protocol shows basic information about devices on …

Fix: 1.42.06162022+
Fix from $1,950 2023-05-22
Iboot Pdu4 N20 Firmware MEDIUM 6.5
CVE-2022-4945

The Dataprobe cloud usernames and passwords are stored in plain text in a specific file. Any user able to read this specific file from the device cou…

Fix: 1.42.06162022+
Fix from $1,600 2023-05-22
Iboot Pdu4 N20 Firmware CRITICAL 9.8
CVE-2022-3183

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the …

Fix: 1.42.06162022+
Fix from $2,300 2022-12-21
Iboot Pdu4 N20 Firmware CRITICAL 9.8
CVE-2022-3184EPSS 12%

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to a…

Fix: 1.42.06162022+
Fix from $2,300 2022-12-21
Iboot Pdu4 N20 Firmware HIGH 7.5
CVE-2022-3186

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the device’s m…

Fix: 1.42.06162022+
Fix from $1,950 2022-12-21
Iboot Pdu4 N20 Firmware MEDIUM 5.3
CVE-2022-3185

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product exposes sensitive data concerning the devic…

Fix: 1.42.06162022+
Fix from $1,600 2022-12-21
Iboot Pdu4 N20 Firmware MEDIUM 5.3
CVE-2022-3187

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is estab…

Fix: 1.42.06162022+
Fix from $1,600 2022-12-21
Iboot Pdu4 N20 Firmware MEDIUM 5.3
CVE-2022-3188

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where unauthenticated users could open PHP index pages without authent…

Fix: 1.42.06162022+
Fix from $1,600 2022-12-21
Iboot Pdu4 N20 Firmware MEDIUM 5.3
CVE-2022-3189

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specially crafted PHP script could use parameters from a HTTP …

Fix: 1.42.06162022+
Fix from $1,600 2022-12-21
Ibootbar Firmware CRITICAL 9.8
CVE-2007-6759

Dataprobe iBootBar (with 2007-09-20 and possibly later released firmware) allows remote attackers to bypass authentication, and conduct power-cycle a…

Fix: after 2007-09-20
Fix from $2,300 2017-04-07
Ibootbar Firmware CRITICAL 9.8
CVE-2007-6760

Dataprobe iBootBar (with 2007-09-20 and possibly later beta firmware) allows remote attackers to bypass authentication, and conduct power-cycle attac…

Fix: after 2007-09-20
Fix from $2,300 2017-04-07