CVE-2021-28204: ASUS BMC's firmware: command injection - Modify user’s information function
The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28204?
CVE-2021-28204 has been classified with a high severity due to its potential for remote command injection.
How do I fix CVE-2021-28204?
To mitigate CVE-2021-28204, upgrade the affected firmware to the latest patched version provided by ASUS.
What systems are affected by CVE-2021-28204?
CVE-2021-28204 specifically affects ASUS Z10PR-D16, ASUS ASMB8-IKVM, and ASUS Z10PE-D16 WS firmware versions 1.14.51 and 1.14.2.
Can CVE-2021-28204 be exploited remotely?
Yes, CVE-2021-28204 can be exploited remotely by attackers with administrator permissions to execute arbitrary commands.
What type of vulnerability is CVE-2021-28204?
CVE-2021-28204 is classified as a command injection vulnerability, which allows an attacker to execute unauthorized commands.