CVE-2023-3263

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the mishandling of special characters when parsing credentials.Successful exploitation allows the malicious agent to obtain a valid authorization token and read information relating to the state of the relays and power distribution.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu4a-c10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu4a-c10:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu4a-c20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu4a-c20:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu4a-n15_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu4a-n15:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu4a-n20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu4a-n20:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu4-c20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu4-c20:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu4-n20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu4-n20:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu4sa-c10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu4sa-c10:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu4sa-c20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu4sa-c20:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu4sa-n15_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu4sa-n15:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu4sa-n20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu4sa-n20:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu8a-2c10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu8a-2c10:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu8a-2c20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu8a-2c20:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu8a-2n15_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu8a-2n15:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu8a-2n20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu8a-2n20:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu8a-c10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu8a-c10:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu8a-c20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu8a-c20:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu8a-n15_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu8a-n15:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu8a-n20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu8a-n20:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu8sa-2n15_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu8sa-2n15:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu8sa-c10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu8sa-c10:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu8sa-n15_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu8sa-n15:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:dataprobe:iboot-pdu8sa-n20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dataprobe:iboot-pdu8sa-n20:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-08-14 05:15

Updated : 2023-08-22 16:24


NVD link : CVE-2023-3263

Mitre link : CVE-2023-3263

CVE.ORG link : CVE-2023-3263


JSON object : View

Products Affected

dataprobe

  • iboot-pdu4a-n15
  • iboot-pdu8a-n20_firmware
  • iboot-pdu4-c20
  • iboot-pdu8a-n20
  • iboot-pdu8sa-c10_firmware
  • iboot-pdu4-n20
  • iboot-pdu8a-2n15
  • iboot-pdu4sa-c20_firmware
  • iboot-pdu8a-2c10_firmware
  • iboot-pdu8a-n15_firmware
  • iboot-pdu4a-c20_firmware
  • iboot-pdu8a-c10_firmware
  • iboot-pdu8a-2c20
  • iboot-pdu8a-2c20_firmware
  • iboot-pdu4a-c10_firmware
  • iboot-pdu4a-c20
  • iboot-pdu8sa-n15
  • iboot-pdu4sa-c10_firmware
  • iboot-pdu4sa-n15_firmware
  • iboot-pdu8sa-n15_firmware
  • iboot-pdu4a-c10
  • iboot-pdu4-n20_firmware
  • iboot-pdu8a-c10
  • iboot-pdu8a-c20_firmware
  • iboot-pdu8sa-2n15
  • iboot-pdu4-c20_firmware
  • iboot-pdu8a-2n15_firmware
  • iboot-pdu8a-2c10
  • iboot-pdu4a-n15_firmware
  • iboot-pdu8a-2n20_firmware
  • iboot-pdu4sa-c20
  • iboot-pdu4a-n20_firmware
  • iboot-pdu8a-n15
  • iboot-pdu4sa-n20_firmware
  • iboot-pdu4sa-c10
  • iboot-pdu8sa-c10
  • iboot-pdu8sa-n20
  • iboot-pdu8sa-2n15_firmware
  • iboot-pdu4a-n20
  • iboot-pdu4sa-n20
  • iboot-pdu4sa-n15
  • iboot-pdu8sa-n20_firmware
  • iboot-pdu8a-c20
  • iboot-pdu8a-2n20
CWE
CWE-287

Improper Authentication

CWE-289

Authentication Bypass by Alternate Name