Database/Firmware, BMC & network fabric

Dataprobe iBoot PDU: Authenticated OS command injection on the PDU
CVE-2023-3260Firmware, BMC & network fabriccurated
Impact
Authenticated OS command injection on the PDU — an attacker who reaches the power controller can cut power to racks, and can pivot from the PDU into the management network
Who can reach it
Network, authenticated
What to do
PDU firmware update to 1.44.08042023; PDUs are rarely in the patch pipeline at all, so the real cost is building one
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.