Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-28205


The specific function in ASUS BMC’s firmware Web management page (Delete SOL video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.


Published

2021-04-06T05:15:17.143

Last Modified

2024-11-21T05:59:21.443

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:C/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

6.9

Weaknesses
  • Type: Secondary
    CWE-22
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System asus z10pr-d16_firmware 1.14.51 Yes
Hardware asus z10pr-d16 - No
Operating System asus asmb8-ikvm_firmware 1.14.51 Yes
Hardware asus asmb8-ikvm - No
Operating System asus z10pe-d16_ws_firmware 1.14.2 Yes
Hardware asus z10pe-d16_ws - No

References