CVE-2022-3186 HIGH

CVE-2022-3186

Vendor Dataprobe
Product iBoot-PDU FW
Weakness CWE-284
Published December 21, 2022
Last update April 15, 2025

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

What the vulnerability does

01Description

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the device’s main management page from the cloud. This feature enables users to remotely connect devices, however, the current implementation permits users to access other device's information.

Key dates

02Disclosure timeline

December 21, 2022 CVE published
April 15, 2025 Record updated