CVE-2023-3260

Publication date

2023-08-14 03:51:52

Family

trellix

State

PUBLISHED

Description

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute arbitrary command on the underlying Linux operating system.