PT-2023-23928 · Dataprobe · Dataprobe Iboot Pdu

Jesse Chick

+1

·

Published

2023-08-13

·

Updated

2023-08-25

·

CVE-2023-3264

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dataprobe iBoot PDU version 1.43.03312023 or earlier
Description The issue concerns the use of hard-coded credentials for interactions with the internal Postgres database and an authentication bypass vulnerability in the REST API due to the mishandling of special characters when parsing credentials. This allows a malicious agent to obtain a valid authorization token, read information relating to the state of the relays and power distribution, and potentially read, modify, or delete arbitrary database records.
Recommendations For version 1.43.03312023 or earlier, as a temporary workaround, consider restricting access to the REST API and the internal Postgres database to minimize the risk of exploitation. Avoid using special characters when parsing credentials in the REST API until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2023-3264

Affected Products

Dataprobe Iboot Pdu