CVE-2021-28203
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD
Description
The Web Set Media Image function in ASUS BMC’s firmware Web management page does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary.
Affected (3)
Products: Asus: Z10pr D16 Firmware, Asmb8 Ikvm Firmware, Z10pe D16 Ws Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.14.51 |
| Running on/with | Platform Versions |
|---|---|
Asus Z10pr D16 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.14.51 |
| Running on/with | Platform Versions |
|---|---|
Asus Asmb8 Ikvm | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.14.2 |
| Running on/with | Platform Versions |
|---|---|
Asus Z10pe D16 Ws | All versions |
References (6)
Source: twcert@cert.org.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.