Dataprobe records
20 published records for vendor dataprobe.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-798 Use of Hard-coded Credentials2
- CWE-287 Improper Authentication2
- CWE-288 Authentication Bypass Using an Alternate Path or Channel2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-256 Plaintext Storage of a Password1
The weakness classes this vendor ships most often: where to look.
CWEAll records
20 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2022-3184No exploit | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated udataprobe · iboot-pdu4-n20 firmware · CWE-22 | Critical9.8 | — | 11.6% | Dec 21, 2022 |
39Monitor | CVE-2007-6760No exploit | Dataprobe iBootBar (with 2007-09-20 and possibly later beta firmware) allows remote attackers to bypass authentication, and conduct power-cydataprobe · ibootbar firmware · CWE-287 | Critical9.8 | — | 1.6% | Apr 7, 2017 |
39Monitor | CVE-2007-6759No exploit | Dataprobe iBootBar (with 2007-09-20 and possibly later released firmware) allows remote attackers to bypass authentication, and conduct powedataprobe · ibootbar firmware · CWE-287 | Critical9.8 | — | 1.6% | Apr 7, 2017 |
39Monitor | CVE-2022-3183No exploit | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input providedataprobe · iboot-pdu4-n20 firmware · CWE-78 | Critical9.8 | — | 1.6% | Dec 21, 2022 |
39Monitor | CVE-2022-46658No exploit | The affected product is vulnerable to a stack-based buffer overflow which could lead to a denial of service or remote code execution.dataprobe · iboot-pdu4-n20 firmware · CWE-121 | Critical9.8 | — | 1.2% | May 22, 2023 |
39Monitor | CVE-2023-3259No exploit | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass.dataprobe · iboot-pdu4a-c10 firmware · CWE-502 | Critical9.8 | — | 1.0% | Aug 14, 2023 |
39Monitor | CVE-2022-46738No exploit | The affected product exposes multiple sensitive data fields of the affected product.dataprobe · iboot-pdu4-n20 firmware · CWE-1391 | Critical9.8 | — | 0.6% | May 22, 2023 |
39Monitor | CVE-2023-3264No exploit | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internaldataprobe · iboot-pdu4a-c10 firmware · CWE-798 | Critical9.8 | — | 0.5% | Aug 14, 2023 |
35Monitor | CVE-2023-3260No exploit | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parametdataprobe · iboot-pdu4a-c10 firmware · CWE-78 | High8.8 | — | 1.3% | Aug 14, 2023 |
35Monitor | CVE-2022-47311No exploit | A proprietary protocol for iBoot devices is used for control and keepalive commands.dataprobe · iboot-pdu4-n20 firmware · CWE-288 | High8.8 | — | 0.5% | May 22, 2023 |
32Monitor | CVE-2022-47320No exploit | The iBoot device’s basic discovery protocol assists in initial device configuration.dataprobe · iboot-pdu4-n20 firmware · CWE-288 | High8.1 | — | 0.5% | May 22, 2023 |
30Monitor | CVE-2023-3263No exploit | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the dataprobe · iboot-pdu4a-c10 firmware · CWE-289 | High7.5 | — | 0.7% | Aug 14, 2023 |
30Monitor | CVE-2022-3186No exploit | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the ddataprobe · iboot-pdu4-n20 firmware · CWE-284 | High7.5 | — | 0.6% | Dec 21, 2022 |
28Monitor | CVE-2023-3261No exploit | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 lidataprobe · iboot-pdu4a-c10 firmware · CWE-119 | High7.2 | — | 0.8% | Aug 14, 2023 |
26Monitor | CVE-2023-3262No exploit | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internaldataprobe · iboot-pdu4a-c10 firmware · CWE-798 | Medium6.7 | — | 0.3% | Aug 14, 2023 |
26Monitor | CVE-2022-4945No exploit | The Dataprobe cloud usernames and passwords are stored in plain text in a specific file.dataprobe · iboot-pdu4-n20 firmware · CWE-256 | Medium6.5 | — | 0.2% | May 22, 2023 |
21Monitor | CVE-2022-3188No exploit | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where unauthenticated users could open PHP index pages withoudataprobe · iboot-pdu4-n20 firmware · CWE-863 | Medium5.3 | — | 0.5% | Dec 21, 2022 |
21Monitor | CVE-2022-3189No exploit | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specially crafted PHP script could use parameters frodataprobe · iboot-pdu4-n20 firmware · CWE-918 | Medium5.3 | — | 0.5% | Dec 21, 2022 |
21Monitor | CVE-2022-3185No exploit | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product exposes sensitive data concerning dataprobe · iboot-pdu4-n20 firmware · CWE-200 | Medium5.3 | — | 0.5% | Dec 21, 2022 |
21Monitor | CVE-2022-3187No exploit | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connectiondataprobe · iboot-pdu4-n20 firmware · CWE-285 | Medium5.3 | — | 0.5% | Dec 21, 2022 |
- CVE-2022-318442Plan
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated u
CriticalCVSS 9.8No exploitEPSS 12%dataprobe · iboot-pdu4-n20 firmwareDec 21, 2022
- CVE-2007-676039Monitor
Dataprobe iBootBar (with 2007-09-20 and possibly later beta firmware) allows remote attackers to bypass authentication, and conduct power-cy
CriticalCVSS 9.8No exploitEPSS 2%dataprobe · ibootbar firmwareApr 7, 2017
- CVE-2007-675939Monitor
Dataprobe iBootBar (with 2007-09-20 and possibly later released firmware) allows remote attackers to bypass authentication, and conduct powe
CriticalCVSS 9.8No exploitEPSS 2%dataprobe · ibootbar firmwareApr 7, 2017
- CVE-2022-318339Monitor
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provide
CriticalCVSS 9.8No exploitEPSS 2%dataprobe · iboot-pdu4-n20 firmwareDec 21, 2022
- CVE-2022-4665839Monitor
The affected product is vulnerable to a stack-based buffer overflow which could lead to a denial of service or remote code execution.
CriticalCVSS 9.8No exploitEPSS 1%dataprobe · iboot-pdu4-n20 firmwareMay 22, 2023
- CVE-2023-325939Monitor
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass.
CriticalCVSS 9.8No exploitEPSS 1%dataprobe · iboot-pdu4a-c10 firmwareAug 14, 2023
- CVE-2022-4673839Monitor
The affected product exposes multiple sensitive data fields of the affected product.
CriticalCVSS 9.8No exploitEPSS 1%dataprobe · iboot-pdu4-n20 firmwareMay 22, 2023
- CVE-2023-326439Monitor
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal
CriticalCVSS 9.8No exploitEPSS 0%dataprobe · iboot-pdu4a-c10 firmwareAug 14, 2023
- CVE-2023-326035Monitor
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL paramet
HighCVSS 8.8No exploitEPSS 1%dataprobe · iboot-pdu4a-c10 firmwareAug 14, 2023
- CVE-2022-4731135Monitor
A proprietary protocol for iBoot devices is used for control and keepalive commands.
HighCVSS 8.8No exploitEPSS 1%dataprobe · iboot-pdu4-n20 firmwareMay 22, 2023
- CVE-2022-4732032Monitor
The iBoot device’s basic discovery protocol assists in initial device configuration.
HighCVSS 8.1No exploitEPSS 1%dataprobe · iboot-pdu4-n20 firmwareMay 22, 2023
- CVE-2023-326330Monitor
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the
HighCVSS 7.5No exploitEPSS 1%dataprobe · iboot-pdu4a-c10 firmwareAug 14, 2023
- CVE-2022-318630Monitor
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the d
HighCVSS 7.5No exploitEPSS 1%dataprobe · iboot-pdu4-n20 firmwareDec 21, 2022
- CVE-2023-326128Monitor
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 li
HighCVSS 7.2No exploitEPSS 1%dataprobe · iboot-pdu4a-c10 firmwareAug 14, 2023
- CVE-2023-326226Monitor
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal
MediumCVSS 6.7No exploitEPSS 0%dataprobe · iboot-pdu4a-c10 firmwareAug 14, 2023
- CVE-2022-494526Monitor
The Dataprobe cloud usernames and passwords are stored in plain text in a specific file.
MediumCVSS 6.5No exploitEPSS 0%dataprobe · iboot-pdu4-n20 firmwareMay 22, 2023
- CVE-2022-318821Monitor
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where unauthenticated users could open PHP index pages withou
MediumCVSS 5.3No exploitEPSS 1%dataprobe · iboot-pdu4-n20 firmwareDec 21, 2022
- CVE-2022-318921Monitor
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specially crafted PHP script could use parameters fro
MediumCVSS 5.3No exploitEPSS 0%dataprobe · iboot-pdu4-n20 firmwareDec 21, 2022
- CVE-2022-318521Monitor
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product exposes sensitive data concerning
MediumCVSS 5.3No exploitEPSS 0%dataprobe · iboot-pdu4-n20 firmwareDec 21, 2022
- CVE-2022-318721Monitor
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection
MediumCVSS 5.3No exploitEPSS 0%dataprobe · iboot-pdu4-n20 firmwareDec 21, 2022