SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-3261

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Successful exploitation could cause denial of service or unexpected behavior with respect to all…

HIGH 7.2EPSS 0.78%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.78%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Successful exploitation could cause denial of service or unexpected behavior with respect to all interactions relying on the targeted vulnerable binary, including the ability to log in via the web server.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.78% probability · 54th percentile
CISA KEV
Not listed
Weakness
CWE-119, CWE-78
Affected
cyberpower/powerpanel server · dataprobe/iboot-pdu4a-c10 firmware · dataprobe/iboot-pdu4a-c20 firmware · dataprobe/iboot-pdu4a-n15 firmware · dataprobe/iboot-pdu4a-n20 firmware · dataprobe/iboot-pdu4-c20 firmware · dataprobe/iboot-pdu4-n20 firmware · dataprobe/iboot-pdu4sa-c10 firmware · dataprobe/iboot-pdu4sa-c20 firmware · dataprobe/iboot-pdu4sa-n15 firmware · dataprobe/iboot-pdu4sa-n20 firmware · dataprobe/iboot-pdu8a-2c10 firmware · dataprobe/iboot-pdu8a-2c20 firmware · dataprobe/iboot-pdu8a-2n15 firmware · dataprobe/iboot-pdu8a-2n20 firmware · dataprobe/iboot-pdu8a-c10 firmware · dataprobe/iboot-pdu8a-c20 firmware · dataprobe/iboot-pdu8a-n15 firmware · dataprobe/iboot-pdu8a-n20 firmware · dataprobe/iboot-pdu8sa-2n15 firmware · +3 more
Source
trellixpsirt@trellix.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.