CVE-2021-28208: ASUS BMC's firmware: path traversal - Get video file function
The specific function in ASUS BMC’s firmware Web management page (Get video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28208?
CVE-2021-28208 is considered a critical vulnerability due to the potential for remote attackers to exploit it via path traversal.
How do I fix CVE-2021-28208?
To fix CVE-2021-28208, update the affected ASUS BMC firmware to the latest version provided by ASUS.
What systems are affected by CVE-2021-28208?
CVE-2021-28208 affects specific ASUS BMC firmware versions, including the ASUS ASMB9-iKVM and several RS700 and RS720 firmware models.
Can CVE-2021-28208 be exploited remotely?
Yes, CVE-2021-28208 can be exploited remotely if an attacker gains administrative access.
What type of vulnerability is CVE-2021-28208?
CVE-2021-28208 is a path traversal vulnerability that allows unauthorized access to system files.