CVE-2021-28207: ASUS BMC's firmware: path traversal - Get Help file function
The specific function in ASUS BMC’s firmware Web management page (Get Help file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28207?
CVE-2021-28207 is considered a high severity vulnerability due to its potential for remote exploitation and unauthorized access to sensitive system files.
How do I fix CVE-2021-28207?
To fix CVE-2021-28207, it is recommended to update the affected ASUS BMC firmware to the latest version that addresses this vulnerability.
What types of devices are affected by CVE-2021-28207?
CVE-2021-28207 affects various ASUS firmware such as ASMB9-IKVM and RS720A-E9-RS24-E, with specific versions being vulnerable.
How can attackers exploit CVE-2021-28207?
Attackers can exploit CVE-2021-28207 via path traversal techniques to gain unauthorized access to sensitive files on the affected system.
Is remote access required to exploit CVE-2021-28207?
Yes, CVE-2021-28207 requires remote access as attackers must obtain administrator permissions to exploit this vulnerability.