Записи Dataprobe
20 опубликованных записей вендора dataprobe.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-798 Use of Hard-coded Credentials2
- CWE-287 Improper Authentication2
- CWE-288 Authentication Bypass Using an Alternate Path or Channel2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-256 Plaintext Storage of a Password1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
20 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2022-3184Эксплойта нет | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated udataprobe · iboot-pdu4-n20 firmware · CWE-22 | Критическая9,8 | — | 11,6 % | 21 дек. 2022 г. |
39Наблюдать | CVE-2007-6760Эксплойта нет | Dataprobe iBootBar (with 2007-09-20 and possibly later beta firmware) allows remote attackers to bypass authentication, and conduct power-cydataprobe · ibootbar firmware · CWE-287 | Критическая9,8 | — | 1,6 % | 7 апр. 2017 г. |
39Наблюдать | CVE-2007-6759Эксплойта нет | Dataprobe iBootBar (with 2007-09-20 and possibly later released firmware) allows remote attackers to bypass authentication, and conduct powedataprobe · ibootbar firmware · CWE-287 | Критическая9,8 | — | 1,6 % | 7 апр. 2017 г. |
39Наблюдать | CVE-2022-3183Эксплойта нет | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input providedataprobe · iboot-pdu4-n20 firmware · CWE-78 | Критическая9,8 | — | 1,6 % | 21 дек. 2022 г. |
39Наблюдать | CVE-2022-46658Эксплойта нет | The affected product is vulnerable to a stack-based buffer overflow which could lead to a denial of service or remote code execution.dataprobe · iboot-pdu4-n20 firmware · CWE-121 | Критическая9,8 | — | 1,2 % | 22 мая 2023 г. |
39Наблюдать | CVE-2023-3259Эксплойта нет | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass.dataprobe · iboot-pdu4a-c10 firmware · CWE-502 | Критическая9,8 | — | 1,0 % | 14 авг. 2023 г. |
39Наблюдать | CVE-2022-46738Эксплойта нет | The affected product exposes multiple sensitive data fields of the affected product.dataprobe · iboot-pdu4-n20 firmware · CWE-1391 | Критическая9,8 | — | 0,6 % | 22 мая 2023 г. |
39Наблюдать | CVE-2023-3264Эксплойта нет | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internaldataprobe · iboot-pdu4a-c10 firmware · CWE-798 | Критическая9,8 | — | 0,5 % | 14 авг. 2023 г. |
35Наблюдать | CVE-2023-3260Эксплойта нет | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parametdataprobe · iboot-pdu4a-c10 firmware · CWE-78 | Высокая8,8 | — | 1,3 % | 14 авг. 2023 г. |
35Наблюдать | CVE-2022-47311Эксплойта нет | A proprietary protocol for iBoot devices is used for control and keepalive commands.dataprobe · iboot-pdu4-n20 firmware · CWE-288 | Высокая8,8 | — | 0,5 % | 22 мая 2023 г. |
32Наблюдать | CVE-2022-47320Эксплойта нет | The iBoot device’s basic discovery protocol assists in initial device configuration.dataprobe · iboot-pdu4-n20 firmware · CWE-288 | Высокая8,1 | — | 0,5 % | 22 мая 2023 г. |
30Наблюдать | CVE-2023-3263Эксплойта нет | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the dataprobe · iboot-pdu4a-c10 firmware · CWE-289 | Высокая7,5 | — | 0,7 % | 14 авг. 2023 г. |
30Наблюдать | CVE-2022-3186Эксплойта нет | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the ddataprobe · iboot-pdu4-n20 firmware · CWE-284 | Высокая7,5 | — | 0,6 % | 21 дек. 2022 г. |
28Наблюдать | CVE-2023-3261Эксплойта нет | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 lidataprobe · iboot-pdu4a-c10 firmware · CWE-119 | Высокая7,2 | — | 0,8 % | 14 авг. 2023 г. |
26Наблюдать | CVE-2023-3262Эксплойта нет | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internaldataprobe · iboot-pdu4a-c10 firmware · CWE-798 | Средняя6,7 | — | 0,3 % | 14 авг. 2023 г. |
26Наблюдать | CVE-2022-4945Эксплойта нет | The Dataprobe cloud usernames and passwords are stored in plain text in a specific file.dataprobe · iboot-pdu4-n20 firmware · CWE-256 | Средняя6,5 | — | 0,2 % | 22 мая 2023 г. |
21Наблюдать | CVE-2022-3188Эксплойта нет | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where unauthenticated users could open PHP index pages withoudataprobe · iboot-pdu4-n20 firmware · CWE-863 | Средняя5,3 | — | 0,5 % | 21 дек. 2022 г. |
21Наблюдать | CVE-2022-3189Эксплойта нет | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specially crafted PHP script could use parameters frodataprobe · iboot-pdu4-n20 firmware · CWE-918 | Средняя5,3 | — | 0,5 % | 21 дек. 2022 г. |
21Наблюдать | CVE-2022-3185Эксплойта нет | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product exposes sensitive data concerning dataprobe · iboot-pdu4-n20 firmware · CWE-200 | Средняя5,3 | — | 0,5 % | 21 дек. 2022 г. |
21Наблюдать | CVE-2022-3187Эксплойта нет | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connectiondataprobe · iboot-pdu4-n20 firmware · CWE-285 | Средняя5,3 | — | 0,5 % | 21 дек. 2022 г. |
- CVE-2022-318442В плане
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated u
КритическаяCVSS 9,8Эксплойта нетEPSS 12 %dataprobe · iboot-pdu4-n20 firmware21 дек. 2022 г.
- CVE-2007-676039Наблюдать
Dataprobe iBootBar (with 2007-09-20 and possibly later beta firmware) allows remote attackers to bypass authentication, and conduct power-cy
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %dataprobe · ibootbar firmware7 апр. 2017 г.
- CVE-2007-675939Наблюдать
Dataprobe iBootBar (with 2007-09-20 and possibly later released firmware) allows remote attackers to bypass authentication, and conduct powe
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %dataprobe · ibootbar firmware7 апр. 2017 г.
- CVE-2022-318339Наблюдать
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provide
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %dataprobe · iboot-pdu4-n20 firmware21 дек. 2022 г.
- CVE-2022-4665839Наблюдать
The affected product is vulnerable to a stack-based buffer overflow which could lead to a denial of service or remote code execution.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dataprobe · iboot-pdu4-n20 firmware22 мая 2023 г.
- CVE-2023-325939Наблюдать
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dataprobe · iboot-pdu4a-c10 firmware14 авг. 2023 г.
- CVE-2022-4673839Наблюдать
The affected product exposes multiple sensitive data fields of the affected product.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dataprobe · iboot-pdu4-n20 firmware22 мая 2023 г.
- CVE-2023-326439Наблюдать
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %dataprobe · iboot-pdu4a-c10 firmware14 авг. 2023 г.
- CVE-2023-326035Наблюдать
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL paramet
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %dataprobe · iboot-pdu4a-c10 firmware14 авг. 2023 г.
- CVE-2022-4731135Наблюдать
A proprietary protocol for iBoot devices is used for control and keepalive commands.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %dataprobe · iboot-pdu4-n20 firmware22 мая 2023 г.
- CVE-2022-4732032Наблюдать
The iBoot device’s basic discovery protocol assists in initial device configuration.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %dataprobe · iboot-pdu4-n20 firmware22 мая 2023 г.
- CVE-2023-326330Наблюдать
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dataprobe · iboot-pdu4a-c10 firmware14 авг. 2023 г.
- CVE-2022-318630Наблюдать
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the d
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dataprobe · iboot-pdu4-n20 firmware21 дек. 2022 г.
- CVE-2023-326128Наблюдать
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 li
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %dataprobe · iboot-pdu4a-c10 firmware14 авг. 2023 г.
- CVE-2023-326226Наблюдать
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal
СредняяCVSS 6,7Эксплойта нетEPSS 0 %dataprobe · iboot-pdu4a-c10 firmware14 авг. 2023 г.
- CVE-2022-494526Наблюдать
The Dataprobe cloud usernames and passwords are stored in plain text in a specific file.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %dataprobe · iboot-pdu4-n20 firmware22 мая 2023 г.
- CVE-2022-318821Наблюдать
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where unauthenticated users could open PHP index pages withou
СредняяCVSS 5,3Эксплойта нетEPSS 1 %dataprobe · iboot-pdu4-n20 firmware21 дек. 2022 г.
- CVE-2022-318921Наблюдать
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specially crafted PHP script could use parameters fro
СредняяCVSS 5,3Эксплойта нетEPSS 0 %dataprobe · iboot-pdu4-n20 firmware21 дек. 2022 г.
- CVE-2022-318521Наблюдать
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product exposes sensitive data concerning
СредняяCVSS 5,3Эксплойта нетEPSS 0 %dataprobe · iboot-pdu4-n20 firmware21 дек. 2022 г.
- CVE-2022-318721Наблюдать
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection
СредняяCVSS 5,3Эксплойта нетEPSS 0 %dataprobe · iboot-pdu4-n20 firmware21 дек. 2022 г.