CVE-2021-28203

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
06/04/2021
Last modified:
14/04/2021

Description

The Web Set Media Image function in ASUS BMC’s firmware Web management page does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:asus:z10pr-d16_firmware:1.14.51:*:*:*:*:*:*:*
cpe:2.3:h:asus:z10pr-d16:-:*:*:*:*:*:*:*
cpe:2.3:o:asus:asmb8-ikvm_firmware:1.14.51:*:*:*:*:*:*:*
cpe:2.3:h:asus:asmb8-ikvm:-:*:*:*:*:*:*:*
cpe:2.3:o:asus:z10pe-d16_ws_firmware:1.14.2:*:*:*:*:*:*:*
cpe:2.3:h:asus:z10pe-d16_ws:-:*:*:*:*:*:*:*