CVE-2021-28205: ASUS BMC's firmware: path traversal - Delete SOL video file function
The specific function in ASUS BMC’s firmware Web management page (Delete SOL video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28205?
The severity of CVE-2021-28205 is medium.
Which ASUS products are affected by CVE-2021-28205?
ASUS Z10pr-d16 Firmware version 1.14.51 and ASUS Asmb8-ikvm Firmware version 1.14.51 are affected by CVE-2021-28205.
What is the vulnerability in ASUS BMC firmware?
The vulnerability in ASUS BMC firmware is a lack of specific parameter filtering in the Delete SOL video file function, which allows remote attackers with administrator permission to access system files through path traversal.
How can remote attackers exploit CVE-2021-28205?
Remote attackers can exploit CVE-2021-28205 by using path traversal to access system files.
Are there any fixes available for CVE-2021-28205?
Please refer to the ASUS Product Security Advisory and contact ASUS support for fixes and updates.