First published: Tue Apr 06 2021(Updated: )
The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
ASUS Z10PR-D16 | =1.14.51 | |
Asus Z11pr-d16 | ||
ASUS ASMB8-IKVM | =1.14.51 | |
ASUS ASMB8-IKVM Firmware | ||
ASUS Z10PE-D16 WS Firmware | =1.14.2 | |
ASUS Z10PE-D16 WS Firmware |
update BMC's firmwares to the following versions: Z10PR-D16 1.16.1 ASMB8-iKVM 1.16.1 Z10PE-D16 WS 1.16.1
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28204 has been classified with a high severity due to its potential for remote command injection.
To mitigate CVE-2021-28204, upgrade the affected firmware to the latest patched version provided by ASUS.
CVE-2021-28204 specifically affects ASUS Z10PR-D16, ASUS ASMB8-IKVM, and ASUS Z10PE-D16 WS firmware versions 1.14.51 and 1.14.2.
Yes, CVE-2021-28204 can be exploited remotely by attackers with administrator permissions to execute arbitrary commands.
CVE-2021-28204 is classified as a command injection vulnerability, which allows an attacker to execute unauthorized commands.