First published: Tue Apr 06 2021(Updated: )
The Web Set Media Image function in ASUS BMC’s firmware Web management page does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
ASUS Z10PR-D16 | =1.14.51 | |
Asus Z11pr-d16 | ||
ASUS ASMB8-IKVM | =1.14.51 | |
ASUS ASMB8-IKVM Firmware | ||
ASUS Z10PE-D16 WS Firmware | =1.14.2 | |
ASUS Z10PE-D16 WS Firmware |
update BMC's firmwares to the following versions: Z10PR-D16 1.16.1 ASMB8-iKVM 1.16.1 Z10PE-D16 WS 1.16.1
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28203 is classified as a high severity vulnerability due to the potential for command injection by remote attackers.
To mitigate CVE-2021-28203, it is recommended to update the firmware to the latest version provided by ASUS.
CVE-2021-28203 affects ASUS BMC firmware versions 1.14.51 and 1.14.2.
CVE-2021-28203 enables remote command injection attacks due to inadequate input filtering.
No, CVE-2021-28203 requires administrator permissions for exploitation.