Back

HIGH

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the device’s main management page from the cloud

Published Dec 21, 2022

Description

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the device’s main management page from the cloud. This feature enables users to remotely connect devices, however, the current implementation permits users to access other device's information.

Affected products

Remediation

Vendor solution

Dataprobe has released the following version update to mitigate these vulnerabilities:

* iBoot-PDU FW: Version 1.42.06162022 https://dataprobe.com/support-iboot-pdu/

Dataprobe also recommends users to disable the SNMP if it is not in use.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner icscert
Published Dec 21, 2022
Updated Apr 15, 2025
Reserved Sep 12, 2022

CISA Vulnrichment

Updated Apr 15, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner icscert
Published Dec 21, 2022
Updated Apr 15, 2025

GitHub

No data