CVE-2023-3261
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
14/08/2023
Last modified:
25/08/2023
Description
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Successful exploitation could cause denial of service or unexpected behavior with respect to all interactions relying on the targeted vulnerable binary, including the ability to log in via the web server.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cyberpower:powerpanel_server:*:*:*:*:enterprise:*:*:* | 2.6.9 (excluding) | |
| cpe:2.3:o:dataprobe:iboot-pdu4a-c10_firmware:*:*:*:*:*:*:*:* | 1.44.0804202 (excluding) | |
| cpe:2.3:h:dataprobe:iboot-pdu4a-c10:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dataprobe:iboot-pdu4a-c20_firmware:*:*:*:*:*:*:*:* | 1.44.0804202 (excluding) | |
| cpe:2.3:h:dataprobe:iboot-pdu4a-c20:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dataprobe:iboot-pdu4a-n15_firmware:*:*:*:*:*:*:*:* | 1.44.0804202 (excluding) | |
| cpe:2.3:h:dataprobe:iboot-pdu4a-n15:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dataprobe:iboot-pdu4a-n20_firmware:*:*:*:*:*:*:*:* | 1.44.0804202 (excluding) | |
| cpe:2.3:h:dataprobe:iboot-pdu4a-n20:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dataprobe:iboot-pdu4-c20_firmware:*:*:*:*:*:*:*:* | 1.44.0804202 (excluding) | |
| cpe:2.3:h:dataprobe:iboot-pdu4-c20:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dataprobe:iboot-pdu4-n20_firmware:*:*:*:*:*:*:*:* | 1.44.0804202 (excluding) | |
| cpe:2.3:h:dataprobe:iboot-pdu4-n20:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dataprobe:iboot-pdu4sa-c10_firmware:*:*:*:*:*:*:*:* | 1.44.0804202 (excluding) | |
| cpe:2.3:h:dataprobe:iboot-pdu4sa-c10:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



