Fiche vulnérabilité
CVE-2023-3260 : faille élevée cyberpower powerpanel server (CVSS 8.8)
Description
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute arbitrary command on the underlying Linux operating system.
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 14 août 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- cyberpower powerpanel server
- dataprobe iboot-pdu4a-c10 firmware
- dataprobe iboot-pdu4a-c20 firmware
- dataprobe iboot-pdu4a-n15 firmware
- dataprobe iboot-pdu4a-n20 firmware
- dataprobe iboot-pdu4-c20 firmware
- dataprobe iboot-pdu4-n20 firmware
- dataprobe iboot-pdu4sa-c10 firmware
- dataprobe iboot-pdu4sa-c20 firmware
- dataprobe iboot-pdu4sa-n15 firmware
- dataprobe iboot-pdu4sa-n20 firmware
- dataprobe iboot-pdu8a-2c10 firmware
- dataprobe iboot-pdu8a-2c20 firmware
- dataprobe iboot-pdu8a-2n15 firmware
- dataprobe iboot-pdu8a-2n20 firmware
- dataprobe iboot-pdu8a-c10 firmware
- dataprobe iboot-pdu8a-c20 firmware
- dataprobe iboot-pdu8a-n15 firmware
- dataprobe iboot-pdu8a-n20 firmware
- dataprobe iboot-pdu8sa-2n15 firmware