Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jesse Chick

#25640of 53,633
9.8Total CVSS
Vulnerabilities · 1
PT-2023-23928
9.8
2023-08-13
Dataprobe · Dataprobe Iboot Pdu · CVE-2023-3264
**Name of the Vulnerable Software and Affected Versions** Dataprobe iBoot PDU version 1.43.03312023 or earlier **Description** The issue concerns the use of hard-coded credentials for interactions with the internal Postgres database and an authentication bypass vulnerability in the REST API due to the mishandling of special characters when parsing credentials. This allows a malicious agent to obtain a valid authorization token, read information relating to the state of the relays and power distribution, and potentially read, modify, or delete arbitrary database records. **Recommendations** For version 1.43.03312023 or earlier, as a temporary workaround, consider restricting access to the REST API and the internal Postgres database to minimize the risk of exploitation. Avoid using special characters when parsing credentials in the REST API until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.