PT-2023-23928 · Dataprobe · Dataprobe Iboot Pdu
Jesse Chick
+1
·
Published
2023-08-13
·
Updated
2023-08-25
·
CVE-2023-3264
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dataprobe iBoot PDU version 1.43.03312023 or earlier
Description
The issue concerns the use of hard-coded credentials for interactions with the internal Postgres database and an authentication bypass vulnerability in the REST API due to the mishandling of special characters when parsing credentials. This allows a malicious agent to obtain a valid authorization token, read information relating to the state of the relays and power distribution, and potentially read, modify, or delete arbitrary database records.
Recommendations
For version 1.43.03312023 or earlier, as a temporary workaround, consider restricting access to the REST API and the internal Postgres database to minimize the risk of exploitation. Avoid using special characters when parsing credentials in the REST API until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dataprobe Iboot Pdu