CVE-2023-3261

HIGH

Cyberpower Powerpanel Server < 2.6.9 - OS Command Injection

Title source: rule
STIX 2.1

Description

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Successful exploitation could cause denial of service or unexpected behavior with respect to all interactions relying on the targeted vulnerable binary, including the ability to log in via the web server.

Scores

CVSS v3 7.5
EPSS 0.0073
EPSS Percentile 49.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-119 CWE-78
Status published
Products (23)
cyberpower/powerpanel_server < 2.6.9
dataprobe/iboot-pdu4-c20_firmware < 1.44.0804202
dataprobe/iboot-pdu4-n20_firmware < 1.44.0804202
dataprobe/iboot-pdu4a-c10_firmware < 1.44.0804202
dataprobe/iboot-pdu4a-c20_firmware < 1.44.0804202
dataprobe/iboot-pdu4a-n15_firmware < 1.44.0804202
dataprobe/iboot-pdu4a-n20_firmware < 1.44.0804202
dataprobe/iboot-pdu4sa-c10_firmware < 1.44.0804202
dataprobe/iboot-pdu4sa-c20_firmware < 1.44.0804202
dataprobe/iboot-pdu4sa-n15_firmware < 1.44.0804202
... and 13 more
Published Aug 14, 2023
Tracked Since Feb 18, 2026