CVE-2023-3262 is a vulnerability in Dataprobe iBoot PDU devices running firmware version 1.43.03312023 or earlier, where hard-coded credentials are used for all interactions with the internal Postgres database. An attacker with the ability to execute OS commands on the device can leverage these credentials to read, modify, or delete arbitrary records in the database, potentially compromising device integrity and data.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small local privilege-escalation PoC set for Ubuntu OverlayFS vulnerabilities CVE-2023-2640 and CVE-2023-3262. It contains three executable Bash scripts and one README. CVE-2023-2640.sh is a minimal behavior test that creates an OverlayFS mount inside a new user/mount namespace via unshare -rm, then lists the merged directory to demonstrate the vulnerable permission-handling context. CVE-2023-3262.sh is the actual privilege-escalation PoC: it copies /usr/bin/python3 into a lowerdir, applies cap_setuid+eip with setcap, mounts an OverlayFS, triggers copy-up with touch m/*, and then executes the resulting upperdir python3 to call os.setuid(0) and spawn /bin/bash as root. exploit_chain.sh combines the technique into a more practical exploit by copying python3 from a globbed path, setting cap_setuid, triggering the OverlayFS behavior, then using Python to become root and create /tmp/rootbash as a SUID-root shell before executing it with -p. There are no network indicators or remote callbacks; the attack vector is strictly local. The repository is a real exploit, not a detector, and provides straightforward operational privilege escalation on vulnerable Ubuntu systems.
This repository contains a local privilege escalation exploit targeting Ubuntu Linux kernels vulnerable to CVE-2023-2640 and CVE-2023-32629. The exploit is implemented as a Bash script (exp.sh) that leverages overlayfs and extended attribute misconfigurations to escalate privileges. The script creates several directories, copies the system Python3 binary, grants it the cap_setuid capability, and mounts an overlay filesystem. It then uses Python to escalate privileges to root, copies /bin/bash to /var/tmp/bash, sets it as setuid root, spawns a root shell, and cleans up all artifacts. The exploit is operational and provides a root shell if run on a vulnerable system. The README provides background on the vulnerabilities, affected kernel versions, and usage instructions. No network endpoints are involved; all actions are local to the target system.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.