Back

CRITICAL

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerability

Published Dec 21, 2022

Description

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerability.

Affected products

Remediation

Vendor solution

Dataprobe has released the following version update to mitigate these vulnerabilities:

* iBoot-PDU FW: Version 1.42.06162022 https://dataprobe.com/support-iboot-pdu/

Dataprobe also recommends users to disable the SNMP if it is not in use.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Dec 21, 2022
Updated Apr 15, 2025
Reserved Sep 12, 2022
CISA Vulnrichment
Updated Apr 15, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a