CVE-2022-3187

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is established with the database. However, these PHP pages do not verify the validity of a user. Attackers could leverage this lack of verification to read the state of outlets.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-263-03 Patch Third Party Advisory US Government Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-263-03 Patch Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu4-n20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu4-n20:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu4sa-n15_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu4sa-n15:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu4a-n15_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu4a-n15:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu4sa-n20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu4sa-n20:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu4a-n20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu4a-n20:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu8sa-n15_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu8sa-n15:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu8a-n15_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu8a-n15:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu8sa-2n15_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu8sa-2n15:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu8a-2n15_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu8a-2n15:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu8sa-n20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu8sa-n20:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu8a-n20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu8a-n20:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu8a-2n20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu8a-2n20:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:19

Type Values Removed Values Added
References () https://www.cisa.gov/uscert/ics/advisories/icsa-22-263-03 - Patch, Third Party Advisory, US Government Resource () https://www.cisa.gov/uscert/ics/advisories/icsa-22-263-03 - Patch, Third Party Advisory, US Government Resource
Summary
  • (es) Las versiones de FW de Dataprobe iBoot-PDU anteriores a 1.42.06162022 contienen una vulnerabilidad donde ciertas páginas PHP solo se validan cuando se establece una conexión válida con la base de datos. Sin embargo, estas páginas PHP no verifican la validez de un usuario. Los atacantes podrían aprovechar esta falta de verificación para leer el estado de los puntos de venta.

Information

Published : 2022-12-21 23:15

Updated : 2024-11-21 07:19


NVD link : CVE-2022-3187

Mitre link : CVE-2022-3187

CVE.ORG link : CVE-2022-3187


JSON object : View

Products Affected

dataprobe

  • iboot-pdu4a-n20_firmware
  • iboot-pdu8sa-n20
  • iboot-pdu8a-n15
  • iboot-pdu8sa-n15
  • iboot-pdu4a-n15_firmware
  • iboot-pdu8a-2n15
  • iboot-pdu4-n20_firmware
  • iboot-pdu8a-2n15_firmware
  • iboot-pdu4-n20
  • iboot-pdu4sa-n20_firmware
  • iboot-pdu8a-2n20
  • iboot-pdu8sa-2n15_firmware
  • iboot-pdu8a-n15_firmware
  • iboot-pdu4sa-n20
  • iboot-pdu4sa-n15
  • iboot-pdu8a-n20_firmware
  • iboot-pdu8sa-n15_firmware
  • iboot-pdu8a-n20
  • iboot-pdu8sa-2n15
  • iboot-pdu4a-n20
  • iboot-pdu8a-2n20_firmware
  • iboot-pdu4sa-n15_firmware
  • iboot-pdu4a-n15
  • iboot-pdu8sa-n20_firmware
CWE
CWE-285

Improper Authorization