Aller au contenu

Fiche vulnérabilité

CVE-2023-3260 : faille élevée cyberpower powerpanel server (CVSS 8.8)

Description

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute arbitrary command on the underlying Linux operating system.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
14 août 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • cyberpower powerpanel server
  • dataprobe iboot-pdu4a-c10 firmware
  • dataprobe iboot-pdu4a-c20 firmware
  • dataprobe iboot-pdu4a-n15 firmware
  • dataprobe iboot-pdu4a-n20 firmware
  • dataprobe iboot-pdu4-c20 firmware
  • dataprobe iboot-pdu4-n20 firmware
  • dataprobe iboot-pdu4sa-c10 firmware
  • dataprobe iboot-pdu4sa-c20 firmware
  • dataprobe iboot-pdu4sa-n15 firmware
  • dataprobe iboot-pdu4sa-n20 firmware
  • dataprobe iboot-pdu8a-2c10 firmware
  • dataprobe iboot-pdu8a-2c20 firmware
  • dataprobe iboot-pdu8a-2n15 firmware
  • dataprobe iboot-pdu8a-2n20 firmware
  • dataprobe iboot-pdu8a-c10 firmware
  • dataprobe iboot-pdu8a-c20 firmware
  • dataprobe iboot-pdu8a-n15 firmware
  • dataprobe iboot-pdu8a-n20 firmware
  • dataprobe iboot-pdu8sa-2n15 firmware

Références

Rechercher une autre vulnérabilité dans la base CVE